Impact
An unauthenticated SQL Injection flaw exists in the getProjectScalings function, caused by insufficient neutralization of special characters in a SQL SELECT statement. A low‑privileged attacker with network access can exploit this weakness to obtain unrestricted database data, resulting in a total loss of confidentiality. The vulnerability is a classic example of CWE‑89, where improper input handling allows control over the database query logic.
Affected Systems
The flaw impacts Helmholz products myREX24V2 and myREX24V2.virtual, as well as MB Connect Line’s mbCONNECT24 and mymbCONNECT24. Version information from the CPE entries indicates that releases up to and including 2.20.0 are affected. Users running these versions should verify whether a newer, patched release is available.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability presents a high severity risk. Exploitation requires only network accessibility; no authentication is necessary, which makes the attack easy to carry out. The EPSS is not available and the issue is not listed in the CISA KEV catalog, but the lack of authentication and the potential for complete data exfiltration push the risk level toward high. If a publicly visible interface is exposed to the internet, the likelihood of exploitation is significant.
OpenCVE Enrichment