CVE-2026-18198 PUBLISHED

SQL Injection in TAC Information's GoldenHorn

Assigner: TR-CERT
Reserved: 29.07.2026 Published: 04.09.2026 Updated: 04.09.2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TAC Information Services Internal and External Trade Inc. GOLDENHORN ONEIT allows Blind SQL Injection.

This issue affects GOLDENHORN ONEIT: before Göbeklitepe.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 8.8

Product Status

Vendor TAC Information Services Internal and External Trade Inc.
Product GOLDENHORN ONEIT
Versions Default: unaffected
  • affected from 0 to Göbeklitepe (excl.)

Credits

  • Muhammed Bilal Kan finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-7 Blind SQL Injection