CVE-2024-4259 MEDIUM

CVE-2024-4259: Sensetive Data Exposure in SAMPAS's AKOS

Vendor Sampaş Holding
Product AKOS (AkosCepVatandasService)
Weakness CWE-862 · Missing authorization
Published September 3, 2024
Last update June 3, 2026

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

Missing Authorization vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users. This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (TahsilatService): before V1.0.7.

Key dates

02Disclosure timeline

September 3, 2024 CVE published
June 3, 2026 Record updated