MB Connect Line mbCONNECT24 and mymbCONNECT24 SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in MB Connect Line's mbCONNECT24 and mymbCONNECT24 applications, specifically in the inmessage model. This vulnerability allows low-privileged remote attackers to exploit an unauthenticated SQL injection flaw by improperly neutralizing special elements in a SQL DELETE command. As a result, attackers can read the entire database and delete entries from a non-critical table, leading to a complete loss of confidentiality and some loss of integrity.

Impact

Exploitation of this vulnerability allows for unauthorized SQL injection, enabling attackers to read the entire database and delete entries from a non-critical table.

Remediation

Users are advised to update their mbCONNECT24 or mymbCONNECT24 instance to version 2.20.1.

Added: May 27, 2026, 9:28 AM
Updated: May 27, 2026, 9:28 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
4.7
remediation
7.7
relevance
9.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.