SQL Injection Vulnerability in User Profile View of Vendor's Product
CVE-2026-40849
7.1HIGH
What is CVE-2026-40849?
A vulnerability exists within the user_alarmprofile view that allows an attacker with low privileges to exploit an unauthenticated SQL Injection. This flaw arises from improper handling of special elements within a SQL SELECT command. Successful exploitation can lead to significant risks, including potential compromises of sensitive user information and a total loss of confidentiality.
Affected Version(s)
mbCONNECT24 0.0.0 <= 2.20.0
mbCONNECT24 2.20.0
mymbCONNECT24 0.0.0 <= 2.20.0
