Improper Privilege Management vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users.This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (TahsilatService): before V1.0.7.
History

Fri, 14 Mar 2025 08:45:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in SAMPAŞ Holding AKOS allows Collect Data as Provided by Users.This issue affects AKOS: through 20240902.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way. Improper Privilege Management vulnerability in SAMPAŞ Holding AKOS (AkosCepVatandasService), SAMPAŞ Holding AKOS (TahsilatService) allows Collect Data as Provided by Users.This issue affects AKOS (AkosCepVatandasService): before V2.0; AKOS (TahsilatService): before V1.0.7.

Thu, 05 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Sambas
Sambas akos
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:sambas:akos:*:*:*:*:*:*:*:*
Vendors & Products Sambas
Sambas akos
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 03 Sep 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Sampas Holding
Sampas Holding akos
CPEs cpe:2.3:a:sampas_holding:akos:*:*:*:*:*:*:*:*
Vendors & Products Sampas Holding
Sampas Holding akos
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 03 Sep 2024 13:30:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in SAMPAŞ Holding AKOS allows Collect Data as Provided by Users.This issue affects AKOS: through 20240902.  NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Sensetive Data Exposure in SAMPAS's AKOS
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published: 2024-09-03T13:15:31.501Z

Updated: 2025-03-14T08:33:26.184Z

Reserved: 2024-04-26T14:40:25.762Z

Link: CVE-2024-4259

cve-icon Vulnrichment

Updated: 2024-09-03T13:36:19.959Z

cve-icon NVD

Status : Modified

Published: 2024-09-03T14:15:17.240

Modified: 2025-03-14T09:15:12.003

Link: CVE-2024-4259

cve-icon Redhat

No data.