Unauthenticated SQL Injection Vulnerability in MBNetJ Admin Interface
CVE-2026-40830
7HIGH
What is CVE-2026-40830?
An unauthenticated SQL Injection vulnerability exists in the admin.mbnetj.php file's UpdateParam function. This flaw allows remote attackers with high privileges to exploit improper neutralization of special elements in SQL UPDATE commands. Successful exploitation can enable attackers to read sensitive data from the entire database and alter values in non-critical tables. Consequently, this can lead to significant breaches of confidentiality and integrity.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
