Executive brief
A critical security flaw has been identified in Windesk.Fm, a facility management software suite. This vulnerability allows unauthorized individuals to manipulate the underlying database, potentially leading to the theft of sensitive corporate data, unauthorized modification of records, or complete loss of system availability. Organizations using this software should update to the latest version immediately to prevent potential ransomware or data breach incidents.
Technical details
A SQL injection vulnerability (CWE-89) exists in Signum Technology Windesk.Fm due to improper neutralization of special elements used in SQL commands. The flaw is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to read, modify, or delete data within the application's database. The vulnerability affects all versions prior to v2.3.4. Although the vendor initially did not respond to disclosure efforts, a patch was eventually released following the public advisory. Security engineers should verify that installations are updated to version 2.3.4 or later.
Affected products
- Signum Technology Promotion and Training Inc. Windesk.Fm before v2.3.4
Timeline
- 2026-02-27: disclosed: Initial disclosure by TR-CERT (USOM)
- 2026-02-27: advisory: CVE-2025-11252 published
- 2026-06-04: patched: Vendor patch confirmed in updated advisory for version 2.3.4