{"id":"CVE-2025-14603","title":"The application component processes user-supplied parameters insecurely, passing them into SQL queries","summary":"The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. \nApply…","severity":"none","published":"2026-08-19","updated":"2026-09-29","sourceUpdated":"2026-09-29T10:10:00.263","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-14603","references":[{"url":"https://github.com/klsecservices/Advisories/blob/master/KLSA-00295-Blind-SQLi-via-User-Input-in-vsDesk.md","label":"vulnerability@kaspersky.com"}],"tags":["nvd"],"ingestedAt":"2026-09-29T10:31:36.299Z","epss":0.00386,"epssPercentile":0.3004,"slug":"CVE-2025-14603","body":"## Overview\n\nThe application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive. \nApply patch from vendor  https://vsdesk.ru/ . Versions 14.0101 and on have the patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}