Executive brief
vsDesk is an application platform that processes customer database queries. A SQL injection vulnerability in its user input handling allows unauthenticated attackers to execute arbitrary SQL commands. Exploitation could expose sensitive database records, cause service outages, or enable unauthorized data access.
Technical details
A blind SQL injection vulnerability exists in vsDesk's application component due to insecure handling of user-supplied parameters passed directly into SQL queries without proper sanitization or parameterization. The vulnerability is network-accessible, requires no authentication or user interaction, and can be exploited to extract database contents through time-based or boolean-based inference techniques, or to trigger denial of service through resource-exhaustive queries. Versions 14.0101 and later include a patch; affected versions include 11.06.02 and other earlier releases. Remediation requires upgrading to the patched version from the vendor at https://vsdesk.ru/.
Affected products
- vsDesk vsDesk before 14.0101
Timeline
- 2026-08-19: disclosed
- 2026: patched: Versions 14.0101 and later contain the patch