Impact
The vsDesk application component accepts user-supplied parameters and incorporates them directly into SQL statements, creating a blind SQL injection weakness. If exploited, an attacker could read sensitive database information or cause the application to become unresponsive, compromising confidentiality of data and thereby impacting availability.
Affected Systems
vulnerable versions of the vsDesk product, before the public patch in release 14.0101, are at risk. The vendor has issued a patch that applies to v14.0101 and later, which can be obtained from the official website.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. EPSS score of 0.00281 is reported, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is an untrusted input path exposed to users via the web interface or API, where an attacker can inject and execute blind SQL queries to exfiltrate data.
OpenCVE Enrichment