Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Mar 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Helmholz
Helmholz myrex24.virtual Helmholz myrex24 V2 Mbconnectline Mbconnectline mbconnect24 Mbconnectline mymbconnect24 |
|
| Vendors & Products |
Helmholz
Helmholz myrex24.virtual Helmholz myrex24 V2 Mbconnectline Mbconnectline mbconnect24 Mbconnectline mymbconnect24 |
Mon, 23 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unauthenticated remote attacker can exploit a Pre-Auth blind SQL Injection vulnerability in the userinfo endpoint’s authentication method due to improper neutralization of special elements in a SQL SELECT command. This can result in a total loss of confidentiality. | |
| Title | Pre-Auth Blind SQLi in userinfo Endpoint | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-03-23T16:01:30.953Z
Reserved: 2026-03-17T09:55:21.859Z
Link: CVE-2026-32969
Updated: 2026-03-23T16:01:22.270Z
Status : Awaiting Analysis
Published: 2026-03-23T12:16:09.090
Modified: 2026-03-23T14:31:37.267
Link: CVE-2026-32969
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:49:18Z