Impact
Improper neutralization of special elements used in an SQL command creates a vulnerability that allows an attacker to inject arbitrary SQL statements. This can lead to unauthorized read, modification, or deletion of database data and may allow privilege escalation within the application. The weakness is a classic SQL Injection (CWE‑89).
Affected Systems
The vulnerability affects Ankara Hosting's Site Management Panel, all releases through the version marked 15062026. No other products or issuers are currently reported to be impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. The EPSS score is not available, and the issue is not listed in CISA’s KEV catalog. The attack vector is likely through the web interface of the Site Management Panel and probably requires authenticated access to the panel, though the description does not explicitly state the authentication requirement. Based on the listed vulnerability type, exploitation would involve crafting malicious input to a vulnerable query without proper parameterization or escaping.
OpenCVE Enrichment