Executive brief
Mavi Yeşil Software's Guest Tracking Software, used for managing visitor information, contains a critical security flaw. This vulnerability allows an attacker to manipulate the underlying database, potentially leading to the theft of sensitive guest data or complete loss of system control. As of the latest report, the vendor has not confirmed a fix, posing a significant risk to organizations using this software.
Technical details
A SQL injection vulnerability (CWE-89) exists in Mavi Yeşil Software Guest Tracking Software due to improper neutralization of special elements used in SQL commands. The vulnerability is remotely exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this flaw to execute arbitrary SQL queries, potentially leading to full database compromise, data exfiltration, or unauthorized administrative access. At the time of reporting, the vendor has not provided information regarding a patch or mitigation.
Affected products
- Mavi Yeşil Software Guest Tracking Software
Timeline
- 2025-06-27: advisory: Initial advisory published by TR-CERT (USOM)