ZeroHour

CVE-2026-18630

niche

SQL Injection in Talassoft Industrial Management Software (V.4 to before V.16)

CVSS 3.1
8.8 high
EPSS
<1%p22
Published
()
Modified
AI analysis

Talassoft Industrial Management Software, an industrial management/ERP product from Turkey's TMT Machine Industry and Trade Ltd. Co., contains a SQL injection flaw (CWE-89) in which user-supplied input is not properly neutralized before being used in SQL commands. The vulnerability is network-exploitable with low attack complexity but requires low-privilege (authenticated) access per the CVSS vector, meaning an attacker with valid credentials on the network-facing application can submit crafted input to vulnerable fields and have arbitrary SQL executed against the backend database. Successful exploitation could expose or alter database contents and disrupt the application, with high confidentiality, integrity, and availability impact per the published CVSS score. All releases from V.4 up to, but not including, V.16 are affected. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates roughly a 0.3% chance of exploitation within 30 days.

What to do: Upgrade Talassoft Industrial Management Software to V.16 or later, the first release outside the affected V.4-to-before-V.16 range. Until upgraded, restrict the application to trusted networks or VPN access, enforce least-privilege application and database accounts, and review database/application logs for signs of SQL injection. Because exploitation requires valid low-privilege credentials, also review and rotate any shared, default, or weak accounts on the system.

Affected
TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management SoftwareAll versions from V.4 before V.16
Estimated exposure
nichelikely hundreds to a few thousand installations at industrial/manufacturing sites — No public install-base, market-share, or internet-scan data exists for this vendor; the estimate reflects the typical footprint of a regional, vertical-market industrial management suite, primarily deployed at manufacturing firms, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows SQL Injection. This issue affects Talassoft Industrial Management Software: from V.4 before V.16.

Weakness
CWE-89
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.