Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Travel APPS: before v17.0.68.
References
| Link | Resource |
|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-24-0809 | |
| https://www.usom.gov.tr/bildirim/tr-24-0809 | Broken Link |
| https://www.usom.gov.tr/bildirim/tr-24-0809 | Broken Link |
Configurations
History
03 Jun 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Travel APPS: before v17.0.68. | |
| References |
|
14 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| Summary | (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68. |
12 Sep 2025, 07:15
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
21 Nov 2024, 08:49
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
| References | () https://www.usom.gov.tr/bildirim/tr-24-0809 - Broken Link |
16 Sep 2024, 17:39
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
| First Time |
Talyabilisim
Talyabilisim travel Apps |
|
| Summary |
|
|
| References | () https://www.usom.gov.tr/bildirim/tr-24-0809 - Broken Link | |
| CPE | cpe:2.3:a:talyabilisim:travel_apps:*:*:*:*:*:*:*:* | |
| CWE | NVD-CWE-noinfo |
27 Jun 2024, 14:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-06-27 14:15
Updated : 2026-06-03 16:16
NVD link : CVE-2024-1153
Mitre link : CVE-2024-1153
CVE.ORG link : CVE-2024-1153
JSON object : View
Products Affected
talyabilisim
- travel_apps
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
NVD-CWE-noinfo