Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hibernate vulnerability in GG Soft Software Services Inc. PaperWork allows Blind SQL Injection, SQL Injection. This issue affects PaperWork: from 6.1.0.9390 before 6.1.0.9398.
https://www.usom.gov.tr/bildirim/tr-25-0381
https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0381