Impact
Netcad Software Inc.'s E-İmar contains a classic SQL injection flaw due to insufficient neutralization of special characters within SQL statements. An attacker who can supply crafted input can cause the application to execute arbitrary SQL commands against the underlying database, potentially leading to unauthorized disclosure, modification, or deletion of sensitive data, and overall compromise of the database.
Affected Systems
Versions of E-İmar from 2.10.1.0 up to, but not including, 3.0.2 are vulnerable. The product affected is Netcad Software Inc.'s E-İmar.
Risk and Exploitability
The CVSS base score of 9.8 signals a critical risk, and the absence of an EPSS score and KEV listing indicates no widespread exploitation has been documented yet but the potential impact remains high. The description does not state authentication requirements; by inference, exploitation would likely occur through injection via publicly accessible form fields or APIs without needing elevated credentials.
OpenCVE Enrichment