CVE-2019-25456

CRITICAL

Web Ofisi Emlak v2 - SQL Injection

Title source: llm

Description

Web Ofisi Emlak v2 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'ara' GET parameter. Attackers can send requests to with time-based SQL injection payloads to extract sensitive database information or cause denial of service.

Exploits (1)

exploitdb WORKING POC
by Ahmet Ümit BAYRAM · textwebappslinux
https://www.exploit-db.com/exploits/47141

Scores

CVSS v3 9.1
EPSS 0.0015
EPSS Percentile 35.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Details

CWE
CWE-89
Status published
Products (2)
web-ofisi/emlak 2.0.0
Web-ofisi/Emlak v2
Published Feb 22, 2026
Tracked Since Feb 22, 2026