CVE-2025-11151
8.2Beyaz Bilgisayar · CityPLus
A vulnerability in Beyaz Bilgisayar CityPLus allows unauthenticated attackers to access unpublicized web pages, leading to the exposure of sensitive system information.
Executive summary
A critical information disclosure vulnerability in Beyaz Bilgisayar CityPLus permits unauthenticated attackers to access sensitive system data, posing a significant risk to organizational confidentiality.
Vulnerability
The software suffers from improper information exposure (CWE-200 and CWE-497), where an unauthenticated remote attacker can discover and access restricted web pages, potentially revealing sensitive system configurations or internal data.
Business impact
The exposure of sensitive system information can provide attackers with the intelligence required to conduct further targeted attacks against the internal network. Given the CVSS score of 8.2, this vulnerability is considered high severity, as it facilitates unauthorized data access without requiring user interaction or authentication. This could lead to a breach of internal operational data and potential regulatory non-compliance.
Remediation
Immediate Action: Update the CityPLus software to version V24.29500.1.0 or later as soon as the vendor makes the patch available.
Proactive Monitoring: Review web server access logs for anomalous requests targeting administrative paths or directories that should not be publicly accessible.
Compensating Controls: Implement strict network access control lists and a Web Application Firewall (WAF) to block unauthorized attempts to browse unpublicized web directories and endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Beyaz Bilgisayar CityPLus must treat this vulnerability with high priority. Given the ease of exploitation, administrators should restrict network access to the affected software until the vendor-supplied update can be verified and deployed. Continuous monitoring of web logs is essential to detect any early signs of reconnaissance or unauthorized data retrieval.
More Beyaz Bilgisayar CVEs
Sources
Originally found and disclosed by Aleyna KABAL, per the CVE Program record.