Cyber Posture

CVE-2024-13148

Critical

Published: 27 February 2025

Published
27 February 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0014 33.7th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yukseloglu Filter B2B Login Platform allows SQL Injection.This issue affects B2B Login Platform: before 16.01.2025.

Security Summary

CVE-2024-13148 is an SQL Injection vulnerability (CWE-89), resulting from improper neutralization of special elements used in an SQL command, in the Yukseloglu Filter B2B Login Platform. This issue affects versions of the B2B Login Platform prior to 16.01.2025.

The vulnerability has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating it is exploitable remotely over the network by unauthenticated attackers with low complexity and no user interaction required. Successful exploitation allows attackers to execute arbitrary SQL commands, potentially leading to high impacts on confidentiality, integrity, and availability, such as unauthorized data access, modification, or deletion.

The USOM advisory (tr-25-0045) at https://www.usom.gov.tr/bildirim/tr-25-0045 provides further details on the vulnerability. Mitigation requires updating the B2B Login Platform to version 16.01.2025 or later.

Details

CWE(s)
CWE-89

References