CVE-2025-8350
Deferred
Deferred - Pending Action
Authentication Bypass and HTTP Response Splitting in BiEticaret CMS
Publication date: 2026-02-19
Last updated on: 2026-06-05
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting.
This issue affects BiEticaret CMS: from 2.1.13 through 19022026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| inrove_software_and_internet_services | bieticaret_cms | From 2.1.13 (inc) to 19022026 (inc) |
| inrove_software | bieticaret_cms | From 2.1.13 (inc) to 19022026 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-698 | The web application sends a redirect to another location, but instead of exiting, it executes additional code. |
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |