CVE-2025-14603
Use of user input in raw SQL queries in vsDesk leading to blind SQL injection
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.ย Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
| Vendor | vsdesk |
| Product | vsdesk |
| Published | Aug 19, 2026 |
Stay Ahead of the Next One
Get instant alerts for vsdesk vsdesk
Be the first to know when new unknown vulnerabilities affecting vsdesk vsdesk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
vsDesk / vsDesk
11.06.02
References
Credits
The vulnerability was discovered by Kirill Nikolaev from Kaspersky (https://kaspersky.com)