Impact
The vulnerability arises from improper neutralization of special characters in user inputs that are incorporated into SQL statements, allowing an attacker to inject malicious SQL code.
Affected Systems
The affected product is Webbeyaz Web Design's Mediküm Web, with security issues present through the 2026-08-07 version. Databases accessed by the application are at risk. The vendor has indicated the product is no longer supported, meaning no official fixes will be issued for this release.
Risk and Exploitability
With a CVSS score of 9.8, this vulnerability is classified as Critical. The EPSS score indicates a very low but nonzero exploitation probability, with a value under 1%. The product is no longer supported, increasing the risk of unmitigated exposure. It is inferred that the attacker could exploit the issue through standard web input channels, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment