Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass.This issue affects CMS: through 10022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.usom.gov.tr/bildirim/tr-26-0050 |
|
History
Tue, 10 Feb 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sarman Soft Software And Technology Services Industry And Trade Ltd. Co.
Sarman Soft Software And Technology Services Industry And Trade Ltd. Co. cms |
|
| Vendors & Products |
Sarman Soft Software And Technology Services Industry And Trade Ltd. Co.
Sarman Soft Software And Technology Services Industry And Trade Ltd. Co. cms |
Tue, 10 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Feb 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Execution After Redirect (EAR) vulnerability in Sarman Soft Software and Technology Services Industry and Trade Ltd. Co. CMS allows JSON Hijacking (aka JavaScript Hijacking), Authentication Bypass.This issue affects CMS: through 10022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | Authentication Bypass in Sarman Soft's CMS | |
| Weaknesses | CWE-698 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TR-CERT
Published: 2026-02-10T13:43:37.928Z
Updated: 2026-02-10T14:47:36.979Z
Reserved: 2025-07-01T11:41:04.863Z
Link: CVE-2025-6967
Updated: 2026-02-10T14:41:42.026Z
Status : Awaiting Analysis
Published: 2026-02-10T14:16:09.607
Modified: 2026-02-10T15:22:54.740
Link: CVE-2025-6967
No data.