Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection. This issue affects Parkmatik: before 02.01-a51.
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
Any version before 02.01-a51
Credits
Resul Melih MACIT
References
www.usom.gov.tr/bildirim/tr-23-0404
www.usom.gov.tr/bildirim/tr-23-0404
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0404