SQL Injection Vulnerability in vsDesk's Application Component
CVE-2025-14603
8.8HIGH
What is CVE-2025-14603?
The vsDesk application component has a vulnerability that allows user-supplied parameters to be processed insecurely. This flaw exposes the application to blind SQL injection attacks, which can facilitate unauthorized access to sensitive database information or lead to the application's unresponsive state. It is crucial for users to apply the recommended patch, available from the vendor, to safeguard their systems. Ensure that your vsDesk software is updated to version 14.0101 or later to mitigate this risk.
Affected Version(s)
vsDesk 11.06.02
vsDesk 14.0101
References
CVSS V4
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)
