Junglewise Threat Intelligence

CVE-2025-8350: Inrove BiEticaret CMS authentication bypass via EAR

CVE-2025-8350 · Severity: critical · CVSS 9.8 · Published 2026-02-19

Executive brief

Inrove BiEticaret CMS, an e-commerce content management system, contains a critical security flaw that allows unauthorized individuals to bypass login requirements. By exploiting this vulnerability, an attacker could gain full administrative access to the online store, potentially compromising customer data, financial transactions, and website operations. The vendor has not yet responded to reports of this issue, and no official patch is currently available.

Technical details

The vulnerability is classified as Missing Authentication for Critical Function (CWE-306) and Execution After Redirect (CWE-698) within the BiEticaret CMS. It occurs because the application fails to terminate the execution process after issuing a redirect command to unauthenticated users, or simply fails to verify identity for sensitive operations. A remote, unauthenticated attacker can exploit this over the network to bypass authentication mechanisms and potentially perform HTTP Response Splitting. This can lead to full compromise of the CMS instance. The issue affects versions 2.1.13 through 19022026; as of the advisory date, the vendor has not provided a fix.

Affected products

  • Inrove Software and Internet Services BiEticaret CMS 2.1.13 through 19022026

Timeline

  • 2026-02-19: advisory: Initial disclosure by USOM/TR-CERT
  • 2026-02-19: disclosed: NVD publication date

References