---
id: CVE-2025-15024
title: >-
  Improper Control of Generation of Code ('Code Injection') vulnerability in
  Yordam Information Technology Consulting, Training and Electronic Systems
  Industry and Trade Inc
summary: >-
  Improper Control of Generation of Code ('Code Injection') vulnerability in
  Yordam Information Technology Consulting, Training and Electronic Systems
  Industry and Trade Inc. Library Automation System allows Remote Code
  Inclusion.


  This is…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
published: '2026-05-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T21:10:00.190'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-15024'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0240'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00246
epssPercentile: 0.14324
ingestedAt: '2026-09-30T21:25:07.730Z'
---

## Overview

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Remote Code Inclusion.

This issue affects Library Automation System: from v.19.5 before v.22.1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
