CVE-2026-18210 PUBLISHED

SQL Injection in TRtek Technological Products's Store

Assigner: TR-CERT
Reserved: 29.07.2026 Published: 01.09.2026 Updated: 01.09.2026

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection.

This issue affects Products's Store: before 030631b2.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company
Product Products's Store
Versions Default: unaffected
  • affected from 0 to 030631b2 (excl.)

Credits

  • Muhammet Talha ODABASI finder
  • Yunus KARA finder

References

Problem Types

  • CWE-89 Improper neutralization of special elements used in an SQL command ('SQL injection') CWE

Impacts

  • CAPEC-66 SQL Injection