Executive brief
Turkguven Perfektive, a business management and operations platform, contains security flaws in its login and authentication mechanisms. These vulnerabilities allow unauthorized individuals to bypass security checks or perform automated password-guessing attacks. If exploited, an attacker could gain unauthorized access to the system, potentially compromising sensitive business data or disrupting operations.
Technical details
Turkguven Perfektive contains multiple authentication-related vulnerabilities including CWE-307 (Improper Restriction of Excessive Authentication Attempts), CWE-602 (Client-Side Enforcement of Server-Side Security), and CWE-807 (Reliance on Untrusted Inputs in a Security Decision). The application fails to properly rate-limit login attempts on the server side and relies on client-side logic or untrusted inputs to make security decisions. A remote, unauthenticated attacker can exploit these flaws to perform brute-force attacks or bypass authentication mechanisms entirely. The issue is resolved in Version 12574 Build 2701.
Affected products
- Turkguven Software Technologies Inc. Perfektive before Version 12574 Build 2701
Timeline
- 2025-11-11: advisory: Initial publication by TR-CERT/USOM
- 2025-11-11: disclosed