CVE-2025-14603: Use of user input in raw SQL queries in vsDesk leading to blind SQL injection
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vsDeskto a version that resolves this vulnerability.Fixed in 14.0101
Event History
Frequently Asked Questions
Which installations need remediation?
vsDesk versions earlier than 14.0101 need remediation. Versions 14.0101 and later include the vendor patch.
What could exploitation allow an attacker to do?
The issue can enable blind SQL injection through insecure handling of user-supplied parameters. This may expose database contents or cause the application to become unresponsive.
What should be done if the affected version is deployed?
Apply the vendor patch by upgrading to vsDesk version 14.0101 or later.