


Perceptive Security
SOC/SIEM Consultancy

WebOfisi E-Ticaret 4.0 contains an SQL injection vulnerability in the 'urun' GET parameter of the endpoint that allows unauthenticated attackers to manipulate d…
Published:
25 maart 2026 om 23:00:00
Alert date:
26 maart 2026 om 16:11:29
Source:
nvd.nist.gov
Web Technologies, Database & Storage
WebOfisi E-Ticaret 4.0 contains a critical SQL injection vulnerability in the 'urun' GET parameter that allows unauthenticated attackers to manipulate database queries. The vulnerability enables multiple attack vectors including boolean-based blind, error-based, time-based blind, and stacked query attacks against the backend database. This represents a high-severity security flaw that could lead to unauthorized data access, modification, or extraction from the affected e-commerce platform.
Technical details
Mitigation steps:
Affected products:
WebOfisi E-Ticaret
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25210
https://drive.google.com/file/d/1ZghFSsYto-Vpv3PXunx8xm2g-Gs3HJwz/view?usp=sharing
https://www.exploit-db.com/exploits/45897
https://www.vulncheck.com/advisories/webofisi-e-ticaret-sql-injection-via-urun-parameter
https://www.web-ofisi.com
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
