9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Information and Communication Technologies Industry and Trade Ltd. Co. Efficiency Management System allows SQL Injection.This issue affects Efficiency Management System: through 03022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Basic Information
ID
CVE-2025-5319
Source
TR-CERT
Published
Feb 3, 2026 at 14:31
Affected Product
Vendor
Emit Information and Communication Technologies Industry and Trade Ltd. Co.
Product
Efficiency Management System
Affected Versions
Emit Information and Communication Technologies Industry and Trade Ltd. Co. Efficiency Management System 0