An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.
| Vendor | Product | Versions |
|---|---|---|
| mb connect line | mbconnect24 | 0.0.0, 0.0.0 |
Updated affected versions to include 2.19.4, changed severity to CRITICAL, and noted that no exploit is available.
Initial creation