


Perceptive Security
SOC/SIEM Consultancy

A SQL injection vulnerability exists in the login functionality of Fikir Odalari AdminPando 1.0.1 before 2026-01-26. The username and password parameters are vu…
Published:
2 februari 2026 om 23:00:00
Alert date:
3 februari 2026 om 21:01:17
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Database & Storage
A critical SQL injection vulnerability in Fikir Odalari AdminPando 1.0.1 allows unauthenticated attackers to bypass authentication through vulnerable username and password parameters in the login functionality. Successful exploitation grants complete administrative access to the application, enabling attackers to manipulate public-facing website content through HTML/DOM manipulation. The vulnerability affects versions before 2026-01-26 and represents a complete authentication bypass, making it a high-severity security issue.
Technical details
Mitigation steps:
Affected products:
Fikir Odalari AdminPando
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-10878
https://github.com/onurcangnc/CVE-2025-10878-AdminPandov1.0.1-SQLi
https://onurcangenc.com.tr/posts/cve-2025-10878-sql-authentication-bypass-in-fikir-odalar%C4%B1-adminpando/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
