MB connect line mbCONNECT24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*
- <= 2.20.0
- 2.20.0
A SQL injection vulnerability has been identified in MB Connect Line's mbCONNECT24 and mymbCONNECT24 applications, specifically in the inmessage model. This vulnerability allows low-privileged remote attackers to exploit an unauthenticated SQL injection flaw by improperly neutralizing special elements in a SQL DELETE command. As a result, attackers can read the entire database and delete entries from a non-critical table, leading to a complete loss of confidentiality and some loss of integrity.
Exploitation of this vulnerability allows for unauthorized SQL injection, enabling attackers to read the entire database and delete entries from a non-critical table.
Users are advised to update their mbCONNECT24 or mymbCONNECT24 instance to version 2.20.1.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.