Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68.
                
            Metrics
Affected Vendors & Products
References
        | Link | Providers | 
|---|---|
| https://www.usom.gov.tr/bildirim/tr-24-0809 | 
                     | 
            
History
                    Tue, 14 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-284 | 
Tue, 14 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Improper Access Control vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68. | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talya Informatics Travel APPS allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Travel APPS: before v17.0.68. | 
| Title | Improper Access Control in Talya Informatics' Travel APPS | SQL Injection Vulnerability in Talya Informatics' Travel APPS | 
| Weaknesses | CWE-89 | 
Fri, 12 Sep 2025 07:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Fri, 12 Sep 2025 06:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        cvssV3_1
         
  | 
    
        
        
        cvssV3_1
         
  | 
Mon, 16 Sep 2024 18:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Talyabilisim
         Talyabilisim travel Apps  | 
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:talyabilisim:travel_apps:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Talyabilisim
         Talyabilisim travel Apps  | 
Status: PUBLISHED
Assigner: TR-CERT
Published: 2024-06-27T13:09:28.115Z
Updated: 2025-10-14T12:36:56.615Z
Reserved: 2024-02-01T12:14:53.148Z
Link: CVE-2024-1153
Updated: 2024-08-01T18:26:30.554Z
Status : Modified
Published: 2024-06-27T14:15:12.957
Modified: 2025-10-14T13:15:34.310
Link: CVE-2024-1153
No data.
ReportizFlow