Impact
An attacker with low privileged remote access can exploit an unauthenticated SQL Injection flaw in the saveDashboardLayout function of the dash.php file. The flaw arises because user input is incorporated into a SQL INSERT statement without proper neutralization of special characters, allowing the attacker to read arbitrary data from the database and insert entries into a non‑critical table. The result is a full loss of confidentiality of database contents and a loss of integrity for at least one table.
Affected Systems
The vulnerability affects Helmholz myREX24V2 and its virtual variant as well as MB connect line mbCONNECT24 and mymbCONNECT24. The impacted versions are indicated as 2.20.0 in the published CPE strings. Affected are the software catalogs for both Helmholz and MB connect line.
Risk and Exploitability
The CVSS score of 7.1 classifies this as a high‑severity flaw. The EPSS score is not available, but the vulnerability is not currently listed in CISA’s KEV catalog. Attackers are likely able to reach the vulnerable endpoint over the network without authentication, making the attack path straightforward for anyone with network visibility to the affected web application. Given the high CVSS and the absence of mitigation indications, the overall risk is moderate to high.
OpenCVE Enrichment