Executive brief
ABIS Technology AVESİS, a platform used for academic information management, contains a security flaw where it incorrectly trusts data sent from a user's browser. An unauthorized attacker can manipulate specific web parameters to bypass access controls and view information or functions they should not be able to see. This could lead to unauthorized access to sensitive academic data or administrative features.
Technical details
A vulnerability classified as CWE-472 (External Control of Assumed-Immutable Web Parameter) exists in ABIS Technology AVESİS versions prior to 202606251646. The application fails to properly validate or protect parameters that are intended to be immutable, such as those used in Access Control List (ACL) checks. A remote, unauthenticated attacker can manipulate these parameters via the network to gain unauthorized access to restricted functionality or data. The vulnerability is addressed in version 202606251646.
Affected products
- ABIS Technology Ltd. Co. AVESİS before 202606251646
Timeline
- 2026-07-24: advisory: CVE published by TR-CERT and NVD
- 2026-06-25: patched: Version 202606251646 released to address the issue