Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.
This issue affects windesk.Fm: before v2.3.4.
NOTE:
The vendor patched the vulnerability after the CVE was published.
References
| Link | Resource |
|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0085 | |
| https://www.usom.gov.tr/bildirim/tr-26-0085 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-02-27 13:16
Updated : 2026-06-17 08:29
NVD link : CVE-2025-11252
Mitre link : CVE-2025-11252
CVE.ORG link : CVE-2025-11252
JSON object : View
Products Affected
signumtte
- windesk.fm
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
