Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.
History

Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Web-ofisi
Web-ofisi emlak
Vendors & Products Web-ofisi
Web-ofisi emlak

Sun, 22 Feb 2026 14:30:00 +0000

Type Values Removed Values Added
Description Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.
Title Web Ofisi Emlak v2 SQL Injection via ara Parameter
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-02-22T14:12:10.439Z

Updated: 2026-02-22T14:12:10.439Z

Reserved: 2026-02-22T13:57:34.791Z

Link: CVE-2019-25456

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-22T15:16:15.187

Modified: 2026-02-23T18:13:53.397

Link: CVE-2019-25456

cve-icon Redhat

No data.