Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

Web Ofisi Platinum E-Ticaret v5: Unauthenticated Access to Sensitive Database Info

CVE-2019-25460
Summary

An attacker can access sensitive database information without a password by sending a special type of request to the website's search function. This could allow the attacker to see confidential data that should not be publicly available. To protect your data, update the affected software or use a web application firewall to block unauthorized access.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
web-ofisi platinum_e-ticaret 5.0.0 –
Original title
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Att...
Original description
Web Ofisi Platinum E-Ticaret v5 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'q' GET parameter. Attackers can send requests to the arama endpoint with malicious 'q' values using time-based SQL injection techniques to extract sensitive database information.
nvd CVSS3.1 7.5
nvd CVSS4.0 8.8
Vulnerability type
CWE-89 SQL Injection
Published: 22 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026