CVE-2025-1929
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.
This issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.46%
- Percentile among all scored CVEs: 38
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1210Exploitation of Remote Serviceslateral movement85 % - Primary impact
T1005Data from Local Systemcollection90 % - Secondary impact
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Secondary impact
T1565.001Stored Data Manipulationimpact80 %
SQL injection (CWE-89) en servicio remoto con PR:H; requiere privilegios autenticados pero sin UI:R, por eso T1210. Impactos: lectura de datos (T1005) e integridad (T1565.001) vía inyección SQL; potencial escalada si el DBMS corre con privilegios elevados (T1068).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-89
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-1929",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-1929",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-08-15T12:54:48.282703Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "iletisim@usom.gov.tr",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.2,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.2
}
]
},
"affected": [
{
"source": "iletisim@usom.gov.tr",
"affectedData": [
{
"vendor": "Risk Yazılım Teknolojileri Ltd. Şti.",
"product": "Reel Sektör Hazine ve Risk Yönetimi Yazılımı",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "custom",
"lessThanOrEqual": "1.0.0.4"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-08-15T12:15:25.203",
"references": [
{
"url": "https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0198",
"source": "iletisim@usom.gov.tr"
},
{
"url": "https://www.usom.gov.tr/bildirim/tr-25-0198",
"source": "iletisim@usom.gov.tr"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "iletisim@usom.gov.tr",
"description": [
{
"lang": "en",
"value": "CWE-89"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Teknolojileri Ltd. Şti. Reel Sektör Hazine ve Risk Yönetimi Yazılımı allows SQL Injection, CAPEC - 7 - Blind SQL Injection.\n\nThis issue affects Reel Sektör Hazine ve Risk Yönetimi Yazılımı: through 1.0.0.4."
},
{
"lang": "es",
"value": "Neutralización inadecuada de elementos especiales utilizados en una vulnerabilidad de comando SQL (\"inyección SQL\") en Risk Yaz?l?m Teknolojileri Ltd. ?ti. Reel Sektör Hazine ve Risk Yönetimi Yaz?l?m? permite la inyección SQL, CAPEC - 7 - Inyección SQL ciega. Este problema afecta a Reel Sektör Hazine ve Risk Yönetimi Yaz?l?m?: hasta 1.0.0.4."
}
],
"lastModified": "2026-06-17T08:40:21.790",
"sourceIdentifier": "iletisim@usom.gov.tr"
}