CVE-2025-2812

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection. This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).
Configurations

Configuration 1 (hide)

cpe:2.3:a:mydata:ticket_sales_automation:*:*:*:*:*:*:*:*

History

06 Jun 2026, 06:16

Type Values Removed Values Added
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection.This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY). (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection. This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY).
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0099 -

28 May 2025, 15:15

Type Values Removed Values Added
References
  • () https://github.com/sahici/CVE-2025-2812/ -

07 May 2025, 17:17

Type Values Removed Values Added
First Time Mydata ticket Sales Automation
Mydata
References () https://www.usom.gov.tr/bildirim/tr-25-0099 - () https://www.usom.gov.tr/bildirim/tr-25-0099 - Third Party Advisory
Summary
  • (es) La vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un comando SQL ('Inyección SQL') en Mydata Informatics Ticket Sales Automation permite la inyección SQL ciega. Este problema afecta a Ticket Sales Automation: antes del 03.04.2025 (DD.MM.AAAA).
CPE cpe:2.3:a:mydata:ticket_sales_automation:*:*:*:*:*:*:*:*

02 May 2025, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-02 09:15

Updated : 2026-06-06 06:16


NVD link : CVE-2025-2812

Mitre link : CVE-2025-2812

CVE.ORG link : CVE-2025-2812


JSON object : View

Products Affected

mydata

  • ticket_sales_automation
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')