SQL injection in Logon Page in MV’s mConnect application, v02.001.00, allows an attacker to use a non existing user with a generic password to connect to the application and get access to unauthorized information.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-23282
Reference (s):
- https://github.com/ifmacedo/mconnect/blob/main/SQLinjection
- https://www.linkedin.com/pulse/mconnect-mv-sql-injection-parcial-iran/

