Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting.This issue affects BiEticaret CMS: from 2.1.13 through 19022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-26-0077 |
|
History
Fri, 20 Feb 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms |
|
| Vendors & Products |
Inrove Software And Internet Services
Inrove Software And Internet Services bieticaret Cms |
Thu, 19 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting.This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Authentication Bypass with Redirect in BiEticaret Software's BiEticaret CMS | |
| Weaknesses | CWE-306 CWE-698 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2026-02-19T11:30:04.046Z
Reserved: 2025-07-30T11:43:48.488Z
Link: CVE-2025-8350
No data.
Status : Awaiting Analysis
Published: 2026-02-19T12:16:14.697
Modified: 2026-02-19T15:52:39.260
Link: CVE-2025-8350
No data.
OpenCVE Enrichment
Updated: 2026-02-20T10:07:13Z