Impact
The CVE describes an SQL injection flaw (CWE-89) in the saveObjectFromData function. A low‑privileged remote attacker can send crafted input that bypasses the neutralization of special characters in a SQL SELECT statement and inject additional commands. The result is that the attacker can read or manipulate any data in the underlying database, leading to a total loss of confidentiality for the affected information.
Affected Systems
Helmholz MyREX24V2 and its virtual edition, as well as the MB connect line products mbCONNECT24 and mymbCONNECT24, are affected. The vulnerability exists in release 2.20.0 for each product as denoted by the component and operating system CPEs.
Risk and Exploitability
The CVSS score of 7.1 assigns this vulnerability to the high‑severity range, indicating significant impact. While the EPSS score is not available and the vulnerability is not listed in CISA KEV, it remains a reasonable severity target for attackers seeking data exfiltration. The flaw can be triggered without authentication over the network once the attacker can reach the saveObjectFromData endpoint; no special privileges or local code execution is required, underscoring its remote nature.
OpenCVE Enrichment