Executive brief
CityPLus, a software solution by Beyaz Bilgisayar, is vulnerable to an information disclosure flaw. This allows unauthorized individuals to discover hidden or unpublicized web pages within the system. An attacker could use this to access sensitive system information or internal administrative interfaces, potentially compromising the privacy and security of the organization's data.
Technical details
An information disclosure vulnerability exists in Beyaz Bilgisayar CityPLus versions prior to V24.29500.1.0. The flaw is categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). It allows a remote, unauthenticated attacker to discover unpublicized web pages and internal system details via the network. This can lead to the exposure of sensitive configuration or administrative data. The issue is resolved in version V24.29500.1.0.
Affected products
- Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus before V24.29500.1.0
Timeline
- 2025-10-21: advisory: NVD published the vulnerability record.