9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kolay Software Inc. Talentics allows Blind SQL Injection.This issue affects Talentics: through 20022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
SQL Injection vulnerability in Talentics allowing Blind SQL Injection
Basic Information
ID
CVE-2025-10970
Source
TR-CERT
Published
Feb 20, 2026 at 11:27
Modified
Feb 20, 2026 at 13:02
Affected Product
Vendor
Kolay Software Inc.
Product
Talentics
Affected Versions
Kolay Software Inc. Talentics 0
CWE Classification
AI Assessment
AI Score
9.8 / 10
AI Severity
Critical
Vendor
Kolay Software Inc.
Product
Talentics
Version
through 20022026