CVE-2025-8350

Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

No configuration.

History

05 Jun 2026, 12:16

Type Values Removed Values Added
Summary (en) Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting.This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0077 -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Ejecución Después de Redirección (EAR), vulnerabilidad de Autenticación Faltante para Función Crítica en Inrove Software e Internet Services BiEticaret CMS permite la Omisión de Autenticación, la División de Respuesta HTTP. Este problema afecta a BiEticaret CMS: desde 2.1.13 hasta 19022026. NOTA: Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

19 Feb 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 12:16

Updated : 2026-06-17 10:06


NVD link : CVE-2025-8350

Mitre link : CVE-2025-8350

CVE.ORG link : CVE-2025-8350


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function

CWE-698

Execution After Redirect (EAR)