Executive brief
A critical security flaw has been identified in Databank Accreditation Software, a tool used for managing accreditation and certification data. This vulnerability allows unauthorized individuals to bypass security checks and gain full access to the underlying database. An attacker could exploit this to steal sensitive information, modify records, or disrupt the software's operations, potentially leading to a total loss of data integrity and confidentiality.
Technical details
The vulnerability is classified as CWE-566 (Authorization Bypass Through User-Controlled SQL Primary Key), which in this implementation leads to SQL Injection. The flaw exists because the application fails to properly validate or sanitize user-supplied primary key values before using them in SQL queries, allowing an attacker to manipulate database transactions. This is a network-based attack that requires no authentication or user interaction. Successful exploitation allows an attacker to read, modify, or delete any data within the database. As of the disclosure date, the vendor has not responded to reports or provided a patch.
Affected products
- DATABASE Software Training Consulting Ltd. Databank Accreditation Software through 19022026
Timeline
- 2026-02-19: disclosed: Initial disclosure by USOM/TR-CERT
- 2026-02-19: advisory: NVD publication date