Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection.

This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs because user input is not properly sanitized before being included in an SQL command. The flaw is the description, it is inferred that an attacker could execute arbitrary SQL statements and therefore read, modify, delete, or exfiltrate database contents that are accessible through the application, compromising confidentiality, integrity, and availability of the stored data.

Affected Systems

The Raera – Ankara Web Design and Digital Advertising Agency’s Destekz web application is affected. Versions released through 02062026 are vulnerable. The vendor has confirmed that this product is no longer supported and that no official patch exists.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical. The EPSS score of under 1% indicates a very low exploitation probability according to current threat data. The product is no longer supported and no fix is available, implying that an attacker can target it without fear of a patch. Based on its nature, the likely attack vector is the web interface that accepts unsanitized user input, enabling the attacker to inject malicious SQL. The combination of critical severity, lack of a fix, and potential for full database compromise brings overall risk to high, and although the vulnerability is not listed in CISA KEV, the lack of support elevates concern.

Generated by OpenCVE AI on July 21, 2026 at 10:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the Destekz application with a modern, supported solution that does not suffer from this vulnerability.
  • Restrict external access to the application through IP rules and monitor for suspicious activity.
  • Deploy a web application firewall or implement server‑side input sanitization and parameterized queries to filter out malicious SQL patterns.

Generated by OpenCVE AI on July 21, 2026 at 10:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Raera
Raera destekz
Vendors & Products Raera
Raera destekz

Mon, 06 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertising Agency Destekz allows SQL Injection. This issue affects Destekz: through 02062026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title SQLi in Raera's Destekz
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-06T17:30:17.328Z

Reserved: 2026-03-17T11:53:19.729Z

Link: CVE-2026-4321

cve-icon Vulnrichment

Updated: 2026-07-06T17:30:13.716Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:15:02Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')