Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information Technologies Ltd. CBS Platform allows SQL Injection. This issue affects CBS Platform: through 09062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Problem types
CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')
Product status
Any version
Credits
Mehmet Abdullah ADBAY
References
siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0344