Description
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection.

This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-07-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper neutralization of special characters in user inputs that are incorporated into SQL statements, allowing an attacker to inject malicious SQL code.

Affected Systems

The affected product is Webbeyaz Web Design's Mediküm Web, with security issues present through the 2026-08-07 version. Databases accessed by the application are at risk. The vendor has indicated the product is no longer supported, meaning no official fixes will be issued for this release.

Risk and Exploitability

With a CVSS score of 9.8, this vulnerability is classified as Critical. The EPSS score indicates a very low but nonzero exploitation probability, with a value under 1%. The product is no longer supported, increasing the risk of unmitigated exposure. It is inferred that the attacker could exploit the issue through standard web input channels, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 29, 2026 at 14:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Phase out the unsupported Webbeyaz Mediküm Web system or migrate to a supported alternative.
  • Deploy a web application firewall or custom input validation to block malicious SQL payloads.
  • Limit the database account privileges used by the application and monitor database logs for anomalies.

Generated by OpenCVE AI on July 29, 2026 at 14:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Webbeyaz Website Design
Webbeyaz Website Design mediküm Web
Vendors & Products Webbeyaz Website Design
Webbeyaz Website Design mediküm Web

Wed, 08 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Injection. This issue affects Mediküm Web: through 08072026. NOTE: The vendor was contacted and it was learned that the product is not supported.
Title SQLi in Webbeyaz's Mediküm Web
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Webbeyaz Website Design Mediküm Web
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T08:54:07.196Z

Reserved: 2026-05-11T12:01:38.201Z

Link: CVE-2026-8307

cve-icon Vulnrichment

Updated: 2026-07-08T14:46:22.417Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:30:03Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')