CVE-2025-14603: Use of user input in raw SQL queries in vsDesk leading to blind SQL injection
The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentially exposing database contents or causing the application to become unresponsive.
Apply patch from vendor https://vsdesk.ru/ . Versions 14.0101 and on have the patch.
Security readout for executives and security teams
Plain-English summary
vsDesk can place unauthenticated user input into raw database queries. A remote attacker may infer sensitive database contents through blind SQL injection or make the application unresponsive. The supplied CVSS 4.0 score is 8.8, indicating high business urgency, particularly for internet-accessible deployments.
Executive priority
Prioritize prompt verification and remediation for internet-accessible vsDesk systems. Potential database disclosure and service disruption justify high urgency, but there is no supplied evidence of active exploitation. Escalate any version ambiguity directly to the vendor before accepting residual risk.
Technical view
CVE-2025-14603 is a network-accessible blind SQL injection with low attack complexity, no privileges, and no user interaction. The supplied vector indicates high confidentiality and availability impact, but no integrity impact. The bundle says version 14.0101 onward is patched, although its affected-version data also lists 14.0101, creating a material version-status conflict.
Likely exposure
Exposure is greatest where vsDesk is reachable from untrusted networks. The supplied evidence identifies 11.06.02 but inconsistently lists 14.0101 as affected while also calling it patched. Exact exposure for other releases cannot be established from this bundle.
Exploitation context
The CVE is not listed as KEV in the supplied data, and no cited source establishes active exploitation. The vulnerability is nevertheless remotely reachable, unauthenticated, and low complexity according to the supplied CVSS vector. Treat this as exploitable risk without claiming observed exploitation.
Researcher notes
The record describes user-controlled parameters entering raw SQL queries and enabling blind SQL injection. CVSS 4.0 is 8.8: AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H. No CWE is supplied. The central evidence gap is the contradictory treatment of version 14.0101; researchers should not infer broader affected ranges.
Mitigation direction
Inventory all vsDesk deployments and record their exact versions and exposure.
Obtain and apply the vendor patch identified for version 14.0101 onward.
Confirm version applicability with vsDesk because the supplied affected-version data conflicts.
Restrict untrusted network access until patch status is verified.
Follow vendor guidance for any additional compensating controls.
Validation and detection
Confirm each deployment's exact installed version and build.
Verify with the vendor whether 14.0101 is patched or affected.
Confirm patched systems report the vendor-supported fixed release.
Review application and database monitoring for unusual request patterns, errors, or availability degradation.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
description · low confidence lookup
Database behavior lookup
The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.