PT-2026-78532 · Vsdesk · Vsdesk

·

CVE-2025-14603

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v4.0

8.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions The product name cannot be determined versions prior to 14.0101
Description An application component insecurely processes user-supplied parameters by passing them into SQL queries. This flaw allows for blind SQL injection, a technique used to extract information from a database by observing the application's response to specific queries, which could lead to the exposure of database contents or cause the application to become unresponsive.
Recommendations Update to version 14.0101 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2025-14603

Affected Products

Vsdesk