Junglewise Threat Intelligence

CVE-2025-15024: Yordam Library Automation System code injection

CVE-2025-15024 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System. Vendors: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc..

Executive brief

A code injection vulnerability has been identified in the Yordam Library Automation System, a platform used for managing library resources and operations. An attacker could exploit this flaw to remotely execute unauthorized code on the system, potentially leading to a full takeover of the library's digital infrastructure. This could result in the theft of sensitive patron data, loss of system availability, or unauthorized modification of library records.

Technical details

The Yordam Library Automation System is vulnerable to Remote Code Inclusion (RCI) due to improper control of code generation (CWE-94). The vulnerability exists in versions 19.5 through 22.1. An unauthenticated remote attacker can exploit this by injecting malicious code that the server then executes. According to the CVSS vector, while the attack is network-based and low complexity, it may require some level of user interaction (UI:R). Successful exploitation allows for complete compromise of confidentiality, integrity, and availability. Users are advised to upgrade to version 22.1 or later to mitigate this risk.

Affected products

  • Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System v.19.5 to v.22.1

Timeline

  • 2026-05-14: advisory: NVD published the vulnerability details.
  • 2026-05-14: disclosed: TR-CERT (Computer Emergency Response Team of the Republic of Turkey) issued a security notification.

References

Related threats