CVE-2025-11252

CRITICAL

Windesk.Fm through 27022026 - SQL Injection

Title source: llm
STIX 2.1

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection. This issue affects windesk.Fm: before v2.3.4.  NOTE:  The vendor patched the vulnerability after the CVE was published.

References (2)

Core 2
Core References
Third Party Advisory, US Government Resource government-resource broken-link
https://www.usom.gov.tr/bildirim/tr-26-0085

Scores

CVSS v3 9.8
EPSS 0.0039
EPSS Percentile 30.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (3)
Signum Technology Promotion and Training Inc./windesk.fm < 27022026
Signum Technology Promotion and Training Inc./windesk.fm < v2.3.4
signumtte/windesk.fm < 27022026
Published Feb 27, 2026
Tracked Since Feb 27, 2026