HIGH🇵🇱 Wersja polska

CVE-2026-33616

CVSS 7.5v3.1pub. 2026-04-02upd. 2026-04-16

An unauthenticated remote attacker can exploit an unauthenticated blind SQL Injection vulnerability in the mb24api endpoint due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Mbconnectline Mbconnect24

    APP
    Mbconnectline
    ≤ 2.19.4
  • Mbconnectline Mymbconnect24

    APP
    Mbconnectline
    ≤ 2.19.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
CWE
References

Related vulnerabilities

CVE-2026-33615CRITICAL9.1PL ✓same product

SQL Injection w endpoincie setinfo produktów Mbconnectline

CVE-2020-35565CRITICAL9.8PL ✓same product

Brak domyślnej ochrony przed brute force w MB CONNECT LINE mymbCONNECT24

CVE-2020-10383CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w MB CONNECT LINE mymbCONNECT24 i mbCONNECT24

CVE-2026-33613HIGH7.2same product

Due to the improper neutralisation of special elements used in an OS command, a remote attacker can exploit an...

CVE-2026-33614HIGH7.5same product

An unauthenticated remote attacker can exploit an unauthenticated SQL Injection vulnerability in the getinfo e...