An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mbconnectline Mbconnect24
cpe:2.3:a:mbconnectline:mbconnect24:*:*:*:*:*:*:*:*
|
— |
<= 2.19.4
|
|
Mbconnectline Mymbconnect24
cpe:2.3:a:mbconnectline:mymbconnect24:*:*:*:*:*:*:*:*
|
— |
<= 2.19.4
|