- Description
- An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
- Source
- info@cert.vde.com
- NVD status
- Analyzed
- Products
- mbconnect24, mymbconnect24
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- info@cert.vde.com
- CWE-89
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FF88F461-51FB-482C-A406-07F72FC10D79",
"versionEndIncluding": "2.19.4",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*",
"matchCriteriaId": "36E8693F-94C4-46A4-BD83-D87B71B89F12",
"versionEndIncluding": "2.19.4",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]