Critical severity9.8NVD Advisory· Published Feb 27, 2026· Updated Jun 4, 2026
CVE-2025-11252
CVE-2025-11252
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.
This issue affects windesk.Fm: before v2.3.4. NOTE: The vendor patched the vulnerability after the CVE was published.
Affected products
2- Range: <2.3.4
Patches
Vulnerability mechanics
References
2- www.usom.gov.tr/bildirim/tr-26-0085nvdThird Party Advisory
- siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0085nvd
News mentions
0No linked articles in our index yet.