Executive brief
A critical security flaw has been identified in the DIGITA Efficiency Management System, a platform used for operational monitoring and efficiency tracking. This vulnerability allows an unauthorized person to manipulate the system's database over the internet without needing a password. An attacker could steal sensitive business data, modify records, or cause a complete system shutdown, potentially disrupting operations and compromising corporate information.
Technical details
The DIGITA Efficiency Management System suffers from an SQL injection vulnerability due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to execute arbitrary SQL queries against the backend database via the network. Successful exploitation can lead to unauthorized data retrieval, modification of database records, and administrative bypass. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed for versions through February 2026.
Affected products
- Emit Informatics and Communication Technologies Industry and Trade Ltd. Co. DIGITA Efficiency Management System through 03022026
Timeline
- 2026-02-03: advisory: Initial disclosure by TR-CERT (USOM)
- 2026-02-03: disclosed: Vendor was contacted prior to disclosure but did not respond.