SQL Injection Vulnerability in Vendor Dashboard of Affected Product
CVE-2026-40844
7.1HIGH
What is CVE-2026-40844?
A low privileged remote attacker can exploit an unauthenticated SQL Injection vulnerability in the vendor's dashboard view. This occurs due to improper handling of special elements within a SQL SELECT command, allowing the attacker to manipulate queries. If successful, this could lead to a significant data breach, resulting in a serious loss of confidentiality and potentially compromising sensitive information.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
