Executive brief
A SQL injection vulnerability exists in Risk Yazılım Teknolojileri's treasury and risk management software. This application is used by businesses to manage financial assets and evaluate market risks. An attacker who successfully exploits this flaw could gain unauthorized access to sensitive financial data, modify records, or disrupt the availability of the risk management system.
Technical details
A blind SQL injection vulnerability (CWE-89) exists in Risk Yazılım Teknolojileri Reel Sektör Hazine ve Risk Yönetimi Yazılımı through version 1.0.0.4. The flaw is caused by improper neutralization of special elements used in SQL commands, specifically categorized under CAPEC-7 (Blind SQL Injection). While the attack vector is network-based, the CVSS metric indicates that high privileges (PR:H) are required to execute the exploit. Successful exploitation allows an attacker to query or manipulate the underlying database, potentially leading to full compromise of data confidentiality, integrity, and availability.
Affected products
- Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı through 1.0.0.4
Timeline
- 2025-08-15: disclosed
- 2025-08-15: advisory