{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-18210",
        "assignerOrgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
        "state": "PUBLISHED",
        "assignerShortName": "TR-CERT",
        "dateReserved": "2026-07-29T08:24:16.460Z",
        "datePublished": "2026-09-01T13:39:27.284Z",
        "dateUpdated": "2026-09-01T14:27:07.293Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "ca940d4e-fea4-4aa2-9a58-591a58b1ce21",
                "shortName": "TR-CERT",
                "dateUpdated": "2026-09-01T14:27:07.293Z"
            },
            "title": "SQL Injection in TRtek Technological Products's Store",
            "datePublic": "2026-09-01T13:37:00.000Z",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-89",
                            "description": "CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection')",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-66",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-66 SQL Injection"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company",
                    "product": "Products's Store",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "0",
                            "lessThan": "030631b2",
                            "versionType": "custom"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection.\n\nThis issue affects Products's Store: before 030631b2.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection.<p>This issue affects Products's Store: before 030631b2.</p>"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0964",
                    "tags": [
                        "government-resource"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "NONE",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "HIGH",
                        "integrityImpact": "HIGH",
                        "availabilityImpact": "HIGH",
                        "baseSeverity": "CRITICAL",
                        "baseScore": 9.8,
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
                    }
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Muhammet Talha ODABASI",
                    "type": "finder"
                },
                {
                    "lang": "en",
                    "value": "Yunus KARA",
                    "type": "finder"
                }
            ],
            "source": {
                "defect": [
                    "TR-26-0964"
                ],
                "advisory": "TR-26-0964",
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.5"
            }
        }
    }
}