Metrics
Affected Vendors & Products
Mon, 23 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Web-ofisi
Web-ofisi ticaret |
|
| Vendors & Products |
Web-ofisi
Web-ofisi ticaret |
Sun, 22 Feb 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' parameter. Attackers can send POST requests to the ajax/productsFilterSearch endpoint with malicious 'q' values using time-based blind SQL injection techniques to extract sensitive database information. | |
| Title | Web Ofisi Platinum E-Ticaret v5 SQL Injection via ajax/productsFilterSearch | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-02-23T21:40:17.722Z
Reserved: 2026-02-22T14:02:58.144Z
Link: CVE-2019-25461
Updated: 2026-02-23T21:40:14.363Z
Status : Awaiting Analysis
Published: 2026-02-22T15:16:16.143
Modified: 2026-02-23T18:13:53.397
Link: CVE-2019-25461
No data.