Executive brief
MevzuatTR, a software platform used for managing legal and regulatory documentation, contains security flaws that could allow attackers to manipulate how the website is displayed to users. By exploiting these vulnerabilities, an attacker could perform phishing attacks or trick users into clicking on hidden interface elements. While the risk is significant, an attacker would first need to obtain high-level administrative privileges within the system to carry out the attack.
Technical details
MevzuatTR versions prior to 12.02.2025 are affected by two primary weaknesses: CWE-79 (Cross-site Scripting) and CWE-1021 (Improper Restriction of Rendered UI Layers or Frames). The root cause is a failure to properly neutralize user-supplied input during web page generation and a lack of restrictive framing headers. A network-based attacker with high privileges can exploit these to perform iFrame overlays, clickjacking, and forceful browsing. The vulnerability allows for the execution of malicious scripts in the context of a user's session or the manipulation of the UI to facilitate phishing. Users are advised to update to the latest version released after February 12, 2025.
Affected products
- Mevzuattr Software MevzuatTR before 12.02.2025
Timeline
- 2025-09-17: disclosed
- 2025-09-17: advisory
- 2025-02-12: patched: Versions before this date are affected.