CVE-2025-7631 PUBLISHED

Time-Based Blind SQLi in Tumeva Internet Technologies' Tumeva News Software

Assigner: TR-CERT
Reserved: 14.07.2025 Published: 17.02.2026 Updated: 17.02.2026

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co. Tumeva News Software allows SQL Injection.This issue affects Tumeva News Software: through 17022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
CVSS Score: 8.6

Product Status

Vendor Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co.
Product Tumeva News Software
Versions Default: affected
  • affected from 0 to 17022026 (incl.)

Credits

  • Çetin BİNİCİ finder

References

Problem Types

  • CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CWE

Impacts

  • CAPEC-66 SQL Injection