Executive brief
Tumeva Prime News Software, a digital news publishing platform, contains a security flaw that allows unauthorized individuals to manipulate its database. By exploiting this vulnerability, an attacker could potentially access sensitive information, modify website content, or disrupt the availability of the news service. This could lead to data theft, reputational damage through site defacement, or significant operational downtime.
Technical details
An SQL injection vulnerability exists in Tumeva Prime News Software due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw allows a remote, unauthenticated attacker to send specially crafted requests to the application over the network. Successful exploitation enables the attacker to execute arbitrary SQL queries against the backend database, potentially leading to unauthorized data retrieval, modification, or a denial-of-service condition. The vulnerability is addressed in version 1.0.2.
Affected products
- Tumeva Internet Technologies Software Prime News Software v1.0.1 to v1.0.2 (exclusive)
Timeline
- 2026-02-17: disclosed
- 2026-02-17: advisory: Initial advisory published by TR-CERT (USOM)
- 2026-06-05: other: Last modified in NVD database