An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the setinfo endpoint due to improper neutralization of special elements in a SQL UPDATE command. This can result in a total loss of integrity and availability.
| Vendor | Product | Versions |
|---|---|---|
| mb connect line | mbconnect24 | 0.0.0, 0.0.0 |
Updated affected versions to include 2.19.4 and corrected exploit availability to false.
Initial creation