---
id: CVE-2025-11151
title: >-
  Exposure of Sensitive Information to an Unauthorized Actor, Exposure of
  Sensitive System Information to an Unauthorized Control Sphere vulnerability
  in Beyaz Bilgisayar Software Design Industry and Trade Ltd
summary: >-
  Exposure of Sensitive Information to an Unauthorized Actor, Exposure of
  Sensitive System Information to an Unauthorized Control Sphere vulnerability
  in Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus
  allows Detect U…
severity: high
cvss: 8.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-200
  - CWE-497
published: '2025-10-21'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11151'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0351'
    label: iletisim@usom.gov.tr
  - url: 'https://www.usom.gov.tr/bildirim/tr-25-0351'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00278
epssPercentile: 0.18312
ingestedAt: '2026-09-30T23:29:32.436Z'
---

## Overview

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Beyaz Bilgisayar Software Design Industry and Trade Ltd. Co. CityPLus allows Detect Unpublicized Web Pages.

This issue affects CityPLus: before V24.29500.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
