PT-2026-21443 · Unknown · Web Ofisi Emlak Version 2

Published

2026-02-22

·

Updated

2026-02-22

·

CVE-2019-25456

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Web Ofisi Emlak version 2
Description The software contains an SQL injection flaw. Unauthenticated attackers can manipulate database queries by injecting SQL code through the ara GET parameter. Attackers can use time-based SQL injection payloads to extract sensitive database information or cause a denial of service.
Recommendations Apply any available updates or patches for Web Ofisi Emlak version 2. As a temporary workaround, restrict access to the ara GET parameter.

Exploit

Fix

DoS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2019-25456

Affected Products

Web Ofisi Emlak Version 2