Home

Description

Missing Authentication, Files or Directories Accessible to External Parties, Use of Hard-coded Credentials vulnerability in Talya Informatics Elektraweb allows Authentication Bypass. This issue affects Elektraweb: before v17.0.68.

PUBLISHED Reserved 2024-01-26 | Published 2024-06-27 | Updated 2026-06-03 | Assigner TR-CERT




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-306 Missing Authentication

CWE-552 Files or Directories Accessible to External Parties

CWE-798 Use of Hard-coded Credentials

Product status

Default status
unaffected

Any version before v17.0.68
affected

Credits

Yusuf Kamil ÇAVUŞOĞLU finder

References

www.usom.gov.tr/bildirim/tr-24-0808

www.usom.gov.tr/bildirim/tr-24-0808 government-resource broken-link

siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-0808 government-resource

cve.org (CVE-2024-0949)

nvd.nist.gov (CVE-2024-0949)

Download JSON