Impact
An unauthenticated SQL injection in the saveDashboardLayout function of dash_layout.php allows a low-privileged remote attacker to insert arbitrary data into a non‑critical table and read the entire database, resulting in a total loss of confidentiality and some loss of integrity.
Affected Systems
Helmholz myREX24V2 and myREX24V2.virtual, version 2.20.0, and MB connect line mbCONNECT24 and mymbCONNECT24, version 2.20.0 are affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. The likely attack path requires network access to the web interface and exploitation of the failure to neutralize special characters in an SQL INSERT command. Successful exploitation gives an attacker the ability to read all database contents and write to a secondary table, which could further be leveraged for persistence or lateral movement.
OpenCVE Enrichment