CVE-2025-2812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).
Configurations

Configuration 1 (hide)

cpe:2.3:a:mydata:ticket_sales_automation:*:*:*:*:*:*:*:*

History

28 May 2025, 15:15

Type Values Removed Values Added
References
  • () https://github.com/sahici/CVE-2025-2812/ -

07 May 2025, 17:17

Type Values Removed Values Added
First Time Mydata ticket Sales Automation
Mydata
References () https://www.usom.gov.tr/bildirim/tr-25-0099 - () https://www.usom.gov.tr/bildirim/tr-25-0099 - Third Party Advisory
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Mydata Informatics Ticket Sales Automation permite la inyección SQL ciega. Este problema afecta a Ticket Sales Automation: antes del 03.04.2025 (DD.MM.AAAA).
CPE cpe:2.3:a:mydata:ticket_sales_automation:*:*:*:*:*:*:*:*

02 May 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 09:15

Updated : 2025-05-28 15:15


NVD link : CVE-2025-2812

Mitre link : CVE-2025-2812

CVE.ORG link : CVE-2025-2812


JSON object : View

Products Affected

mydata

  • ticket_sales_automation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')