PatchSiren

Ekol Informatics CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Ekol Informatics CVE published 2024-01-02

CVE-2023-6436

CVE-2023-6436 is a critical SQL injection vulnerability affecting Ekolbilisim Web Sablonu Yazilimi, also described in the source record as Ekol Informatics Website Template, through version 20231215. The NVD record classifies the issue as CWE-89 and assigns a CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a remotely reachable issue with no privileges or user interaction required a [truncated]