Impact
The vulnerability occurs because user input is not properly sanitized before being included in an SQL command. The flaw is the description, it is inferred that an attacker could execute arbitrary SQL statements and therefore read, modify, delete, or exfiltrate database contents that are accessible through the application, compromising confidentiality, integrity, and availability of the stored data.
Affected Systems
The Raera – Ankara Web Design and Digital Advertising Agency’s Destekz web application is affected. Versions released through 02062026 are vulnerable. The vendor has confirmed that this product is no longer supported and that no official patch exists.
Risk and Exploitability
The CVSS score of 9.8 marks this flaw as critical. The EPSS score of under 1% indicates a very low exploitation probability according to current threat data. The product is no longer supported and no fix is available, implying that an attacker can target it without fear of a patch. Based on its nature, the likely attack vector is the web interface that accepts unsanitized user input, enabling the attacker to inject malicious SQL. The combination of critical severity, lack of a fix, and potential for full database compromise brings overall risk to high, and although the vulnerability is not listed in CISA KEV, the lack of support elevates concern.
OpenCVE Enrichment