Impact
A remote attacker can use an unauthenticated SQL Injection in the getinfo endpoint because special characters are not properly neutralized in the SQL SELECT command. This allows the attacker to read arbitrary database contents, leading to a total loss of confidentiality. The weakness is a classic input validation flaw and is classified under CWE-89.
Affected Systems
The vulnerability affects MB connect line products, specifically mbCONNECT24 and mymbCONNECT24. No specific version information is provided in the advisory, so all deployed instances of these products are potentially exposed.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. Exploitation is likely since the attack requires no authentication and can be performed over the network via an HTTP request to the getinfo endpoint. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the lack of a patch and the high score suggest a significant risk of exploitation.
OpenCVE Enrichment