Home

Description

Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Publishing and Advertising, Education Ltd. Co. DijiDemi allows Privilege Abuse. This issue affects DijiDemi: from v4.5.12.1 before v4.5.13.0.

PUBLISHED Reserved 2026-04-09 | Published 2026-05-14 | Updated 2026-05-14 | Assigner TR-CERT




MEDIUM: 6.8CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-639 Authorization bypass through User-Controlled key

Product status

Default status
unaffected

v4.5.12.1 (custom) before v4.5.13.0
affected

Credits

Muhammet Emirhan SÜMER finder

References

siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0239 government-resource

cve.org (CVE-2026-6008)

nvd.nist.gov (CVE-2026-6008)

Download JSON