{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-13506",
        "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "state": "PUBLISHED",
        "assignerShortName": "TR-CERT",
        "dateReserved": "2025-11-21T12:14:27.616Z",
        "datePublished": "2025-12-12T12:19:37.226Z",
        "dateUpdated": "2026-06-04T06:31:59.267Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
                "shortName": "TR-CERT",
                "dateUpdated": "2026-06-04T06:31:59.267Z"
            },
            "title": "Improper Authorization in Nebim Neyir's Nebim V3 ERP",
            "datePublic": "2025-12-12T12:18:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-250",
                            "description": "CWE-250 Execution with Unnecessary Privileges",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-470",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-470 Expanding Control over the Operating System from the Database"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Nebim Neyir Computer Industry and Services Inc.",
                    "product": "Nebim V3 ERP",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "2.0.59",
                            "lessThan": "3.0.1",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allows Expanding Control over the Operating System from the Database.\n\nThis issue affects Nebim V3 ERP: from 2.0.59 before 3.0.1.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Execution with Unnecessary Privileges vulnerability in Nebim Neyir Computer Industry and Services Inc. Nebim V3 ERP allows Expanding Control over the Operating System from the Database.<p>This issue affects Nebim V3 ERP: from 2.0.59 before 3.0.1.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://www.usom.gov.tr/bildirim/tr-25-0450",
                    "tags": [
                        "government-resource",
                        "broken-link"
                    ]
                },
                {
                    "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0450",
                    "tags": [
                        "government-resource"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Mehmet Tolga DEMİRCİ",
                    "type": "finder"
                }
            ],
            "source": {
                "defect": [
                    "TR-25-0450"
                ],
                "advisory": "TR-25-0450",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-12-12T14:30:32.135685Z",
                                "id": "CVE-2025-13506",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-12-12T14:30:42.870Z"
                }
            }
        ]
    }
}