Improper Access Control in Premierturk's Excavation Management Information System
Summary
| CVE | CVE-2025-11959 |
|---|---|
| State | PUBLISHED |
| Assigner | TR-CERT |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-11-11 15:15:35 UTC |
| Updated | 2026-04-15 00:35:42 UTC |
| Description | Files or Directories Accessible to External Parties, Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Premierturk Information Technologies Inc. Excavation Management Information System allows Footprinting, Functionality Misuse. This issue affects Excavation Management Information System: before v.10.2025.01. |
Risk And Classification
Primary CVSS: v3.1 8.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
EPSS: 0.000410000 probability, percentile 0.128350000 (date 2026-06-04)
Problem Types: CWE-359 | CWE-552 | CWE-552 CWE-552 Files or Directories Accessible to External Parties | CWE-359 CWE-359 Exposure of Private Personal Information to an Unauthorized Actor
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | CNA | CVSS | 8.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Premierturk Information Technologies Inc. | Excavation Management Information System | affected v.10.2025.01 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.usom.gov.tr/bildirim/tr-25-0388 | [email protected] | www.usom.gov.tr | |
| siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0388 | https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0388 | siberguvenlik.gov.tr | government-resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: İbrahim YİĞİTSOY (en)
There are currently no legacy QID mappings associated with this CVE.