Executive brief
Webbeyaz Mediküm Web, a web-based platform, contains a critical security flaw that allows unauthorized individuals to manipulate its database. An attacker could use this vulnerability to steal sensitive customer data, modify records, or disrupt the service entirely. Because the vendor no longer supports this product, no official security updates will be released to fix this issue.
Technical details
A SQL injection vulnerability exists in Webbeyaz Web Design Mediküm Web due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is remotely exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can leverage this to perform unauthorized data exfiltration, modification, or deletion within the backend database. The vendor has confirmed the product is end-of-life (EOL) and no longer supported, meaning no patch is available.
Affected products
- Webbeyaz Web Design Mediküm Web through 08072026
Timeline
- 2026-07-08: advisory: NVD and TR-CERT published the advisory
- 2026-07-08: other: Vendor confirmed product is no longer supported