{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2025-14603", "assignerOrgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988", "state": "PUBLISHED", "assignerShortName": "Kaspersky", "dateReserved": "2025-12-12T18:42:16.828Z", "datePublished": "2026-08-19T17:16:08.456Z", "dateUpdated": "2026-08-19T19:05:52.839Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e45d732a-8f6b-4b6b-be76-7420f6a2b988", "shortName": "Kaspersky", "dateUpdated": "2026-08-19T17:16:08.456Z" }, "title": "Use of user input in raw SQL queries in vsDesk leading to blind SQL injection", "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE 89 SQL Injection" } ] } ], "impacts": [ { "capecId": "CAPEC-7", "descriptions": [ { "lang": "en", "value": "CAPEC-7: Blind SQL Injection" } ] } ], "affected": [ { "vendor": "vsDesk", "product": "vsDesk", "versions": [ { "status": "affected", "version": "11.06.02" }, { "status": "unaffected", "version": "14.0101" } ], "defaultStatus": "unknown" } ], "descriptions": [ { "lang": "en", "value": "The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. \nApply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/. Versions 14.0101 and on have the patch.