Junglewise Threat Intelligence

CVE-2025-10439: Yordam Informatics Yordam Library Automation System SQL injection

CVE-2025-10439 · Severity: critical · CVSS 9.8 · Published 2025-09-17

Executive brief

A critical security vulnerability has been identified in the Yordam Library Automation System, a platform used to manage library collections and operations. This flaw allows unauthorized individuals to manipulate the system's database over the internet without needing a username or password. An attacker could use this to steal sensitive patron data, modify library records, or disrupt the availability of the library's digital services.

Technical details

An SQL injection vulnerability exists in Yordam Informatics Yordam Library Automation System due to improper neutralization of special elements used in SQL commands (CWE-89). The flaw is reachable over the network and requires no prior authentication or user interaction. By sending specially crafted requests, an attacker can bypass security controls to view, modify, or delete data within the underlying database. The issue affects versions 21.5 and 21.6, and has been addressed in version 21.7.

Affected products

  • Yordam Informatics Yordam Library Automation System 21.5 and 21.6 before 21.7

Timeline

  • 2025-09-17: disclosed
  • 2025-09-17: advisory

References