CVE-2025-15024: RCE in Yordam Informatics' Library Automation System
Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Remote Code Inclusion.
This issue affects Library Automation System: from v.19.5 before v.22.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-15024?
CVE-2025-15024 is categorized with a high severity due to its potential for remote code execution.
How do I fix CVE-2025-15024?
To fix CVE-2025-15024, update the Yordam Informatics Library Automation System to a version later than 22.1.
What is affected by CVE-2025-15024?
CVE-2025-15024 affects versions of Yordam Informatics Library Automation System between 19.5 and 22.1.
What type of vulnerability is CVE-2025-15024?
CVE-2025-15024 is a code injection vulnerability allowing remote code inclusion.
What does CVE-2025-15024 allow an attacker to do?
CVE-2025-15024 allows an attacker to execute arbitrary code on the affected system remotely.