Executive brief
A critical security vulnerability exists in ESBI Auto Service Software, a management platform for automotive service businesses. An attacker can remotely access and manipulate the underlying database without needing a username or password. This could lead to the theft of sensitive customer data, alteration of financial records, or a complete shutdown of the service operations.
Technical details
A SQL injection vulnerability (CWE-89) exists in ESBI Auto Service Software due to improper neutralization of special elements used in SQL commands. The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application to execute arbitrary SQL queries. Successful exploitation grants the attacker full access to read, modify, or delete data within the database, potentially leading to full system compromise. The issue is resolved in version 2025.10.01.
Affected products
- ESBI Information and Telecommunication Industry and Trade Limited Company Auto Service Software before v.2025.10.01
Timeline
- 2025-09-18: advisory: Initial disclosure by TR-CERT (USOM)
- 2025-10-01: patched: Vendor released version 2025.10.01 to address the vulnerability