CVE-2019-25458 HIGH

CVE-2019-25458: Web Ofisi Firma Rehberi v1 SQL Injection via firmalar.html

Vendor Web-Ofisi
Product Firma Rehberi
Weakness CWE-89 · SQLi
Published February 22, 2026
Last update April 7, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Web Ofisi Firma Rehberi v1 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through GET parameters. Attackers can send requests to with malicious payloads in the 'il', 'kat', or 'kelime' parameters to extract sensitive database information or perform time-based blind SQL injection attacks.

Key dates

02Disclosure timeline

February 22, 2026 CVE published
April 7, 2026 Record updated