Unauthenticated SQL Injection in Vendor's Product Affecting Data Integrity
CVE-2026-40842
7.1HIGH
What is CVE-2026-40842?
An unauthenticated SQL injection vulnerability exists within the getWidgetTags function in Vendor's Product. This flaw arises from improper handling of special characters in a SQL SELECT command, allowing a remote attacker with low privileges to manipulate database queries. Exploitation of this vulnerability may lead to unauthorized data exposure, compromising the confidentiality of sensitive information.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
