EIP-2026-108967
PRE-CVEKarakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-108967. PoCs published by Hakan TAŞKÖPRÜ.
AI-analyzed exploit summary This exploit demonstrates multiple unauthenticated vulnerabilities in Karakuzu ERP Management Web 5.7.0, including SQL injection (error-based and time-based), stored XSS, and unauthorized user management (creation, deletion, and editing). The payloads are functional and target specific parameters in HTTP POST requests.
Description
Karakuzu ERP Management Web 5.7.0 - 'k_adi_duz' SQL Injection
Exploits (1)
This exploit demonstrates multiple unauthenticated vulnerabilities in Karakuzu ERP Management Web 5.7.0, including SQL injection (error-based and time-based), stored XSS, and unauthorized user management (creation, deletion, and editing). The payloads are functional and target specific parameters in HTTP POST requests.