Metrics
Affected Vendors & Products
Link | Providers |
---|---|
https://www.usom.gov.tr/bildirim/tr-25-0273 |
![]() ![]() |
Fri, 03 Oct 2025 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-566 |
Fri, 03 Oct 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Logo Software Diva allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Diva: through 4.56.00.00. | CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software allows SQL Injection.This issue affects Auto Service Software: before v.2025.10.01. |
Title | SQLi in Logo Software's Diva | SQLi in ESBI Informatics's Auto Service Software |
Metrics |
cvssV3_1
|
cvssV3_1
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Logo Software
Logo Software diva |
|
Vendors & Products |
Logo Software
Logo Software diva |
Thu, 18 Sep 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Logo Software Retail Sales Management allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Retail Sales Management: through 20250918. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available. | Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Logo Software Diva allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Diva: through 4.56.00.00. |
Title | SQLi in Logo Software's Retail Sales Management | SQLi in Logo Software's Diva |
Thu, 18 Sep 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 18 Sep 2025 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Authorization Bypass Through User-Controlled SQL Primary Key, CWE - 89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Logo Software Retail Sales Management allows SQL Injection, CAPEC - 7 - Blind SQL Injection.This issue affects Retail Sales Management: through 20250918. NOTE: The vendor did not inform about the completion of the fixing process within the specified time. The CVE will be updated when new information becomes available. | |
Title | SQLi in Logo Software's Retail Sales Management | |
Weaknesses | CWE-566 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2025-10-03T12:19:32.604Z
Reserved: 2025-01-06T14:04:42.376Z
Link: CVE-2024-13151

Updated: 2025-09-18T13:25:55.229Z

Status : Awaiting Analysis
Published: 2025-09-18T12:15:36.260
Modified: 2025-10-03T13:15:45.463
Link: CVE-2024-13151

No data.

Updated: 2025-09-22T10:06:33Z