Impact
SQL Injection vulnerability in the alarming view arises from improper neutralization of special characters in a SELECT statement. As described, a low‑privileged remote attacker can inject malicious SQL without prior authentication, potentially gaining full access to data stored in the database. Successful exploitation results in a total loss of confidentiality.
Affected Systems
Affected vendors are Helmholz and MB Connect Line. The vulnerable products include myREX24V2, myREX24V2.virtual, mbCONNECT24, and mymbCONNECT24. All are impacted in version 2.20.0, as indicated by the Common Platform Enumeration entries.
Risk and Exploitability
The CVSS score of 7.1 classifies it as a high‑severity flaw with a considerable risk of exploitation. The EPSS score is not available, but the remote attack vector and lack of authentication requirements make the vulnerability attractive to threat actors. Although it is not listed in the CISA KEV catalog, the potential for data compromise warrants urgent attention.
OpenCVE Enrichment