Executive brief
Inrove BiEticaret, an e-commerce platform, contains a critical security flaw that allows unauthorized individuals to manipulate its database. By exploiting this vulnerability, an attacker could steal sensitive customer information, modify product data, or disrupt the website's operations entirely. This issue poses a significant risk to data privacy and business continuity for organizations using the affected software.
Technical details
A SQL injection vulnerability exists in Inrove Software and Internet Services BiEticaret due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to execute arbitrary SQL queries against the backend database. This can lead to full data exfiltration, unauthorized modification of records, or administrative bypass. The issue is resolved in version v3.3.57.
Affected products
- Inrove Software and Internet Services BiEticaret before v3.3.57
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory