« Volver al listado

CVE-2023-4674

Estado: ModificadaSin puntuar—

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection.

This issue affects E-Commerce Software: through 20231229.

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-4674",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "iletisim@usom.gov.tr",
      "affectedData": [
        {
          "vendor": "Yaztek Software Technologies and Computer Systems",
          "product": "E-Commerce Software",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "20231229"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-29T15:15:09.497",
  "references": [
    {
      "url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0741",
      "source": "iletisim@usom.gov.tr"
    },
    {
      "url": "https://www.usom.gov.tr/bildirim/tr-23-0741",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "iletisim@usom.gov.tr"
    },
    {
      "url": "https://www.usom.gov.tr/bildirim/tr-23-0741",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "iletisim@usom.gov.tr",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-89"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yaztek Software Technologies and Computer Systems E-Commerce Software allows SQL Injection.\n\nThis issue affects E-Commerce Software: through 20231229. \n\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way."
    },
    {
      "lang": "es",
      "value": "Neutralización incorrecta de elementos especiales utilizados en una vulnerabilidad de comando SQL (\"Inyección SQL\") en Yaztek Software Technologies and Computer Systems E-Commerce Software. El software de comercio electrónico permite la inyección de SQL. Este problema afecta a E-Commerce Software: hasta 20231229. NOTA: Se contactó primeramente al proveedor sobre esta divulgación, pero no respondió de nignuna forma."
    }
  ],
  "lastModified": "2026-06-17T06:38:20.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:yaztekteknoloji:e-commerce:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4CC1C6D0-8710-4F69-8FB9-0620CBC2ED92",
              "versionEndIncluding": "20231229"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "iletisim@usom.gov.tr"
}