PT-2026-21443 · Unknown · Web Ofisi Emlak Version 2

CVE-2019-25456

·

Publicado

2026-02-22

·

Atualizado

2026-02-22

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Web Ofisi Emlak version 2
Description The software contains an SQL injection flaw. Unauthenticated attackers can manipulate database queries by injecting SQL code through the ara GET parameter. Attackers can use time-based SQL injection payloads to extract sensitive database information or cause a denial of service.
Recommendations Apply any available updates or patches for Web Ofisi Emlak version 2. As a temporary workaround, restrict access to the ara GET parameter.

Exploit

Correção

DoS

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25456

Produtos afetados

Web Ofisi Emlak Version 2