External Control Vulnerability in AVESİS by ABIS Technology Ltd.
CVE-2026-7484
5.3MEDIUM
What is CVE-2026-7484?
A vulnerability in ABIS Technology Ltd.'s AVESİS software permits unauthorized access by exploiting an external control of an assumed-immutable web parameter. This flaw arises due to the Access Control Lists (ACLs) not properly constraining access to certain functionalities, potentially allowing attackers to perform unauthorized actions. Users of AVESİS versions prior to 202606251646 should take immediate steps to mitigate this security risk.
Affected Version(s)
AVESİS 0 < 202606251646
