SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2025-14603

HIGH · CVSS 8.8 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability arises from the application component's insecure handling of user-supplied parameters, allowing for blind SQL injection attacks. This could lead to unauthorized access to sensitive database contents or application downtime. Organizations using affected versions should prioritize applying the vendor's patch to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-14603
Severity
HIGH
CVSS
8.8
EPSS
0.28%

Original NVD Description

The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.  Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.