Unauthenticated SQL Injection in Affected Product by Vendor
CVE-2026-40841
7.1HIGH
What is CVE-2026-40841?
A low-privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getProjectTags function due to improper handling of input within a SQL SELECT command. This flaw can lead to significant data exposure, potentially allowing attackers to manipulate queries and retrieve sensitive information, resulting in a total compromise of data confidentiality.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
