CVE-2025-11252

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2.3.4.  NOTE:  The vendor patched the vulnerability after the CVE was published.
References
Link Resource
https://www.usom.gov.tr/bildirim/tr-26-0085 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:signumtte:windesk.fm:*:*:*:*:*:*:*:*

History

16 Apr 2026, 16:16

Type Values Removed Values Added
Summary
  • (es) La vulnerabilidad de Neutralización Incorrecta de Elementos Especiales utilizados en un Comando SQL ('inyección SQL') en Signum Technology Promotion and Training Inc. Windesk.Fm permite la inyección SQL. Este problema afecta a windesk.Fm: hasta el 27022026. NOTA: Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.
Summary (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: through 27022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. (en) Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology Promotion and Training Inc. Windesk.Fm allows SQL Injection.This issue affects windesk.Fm: before v2.3.4.  NOTE:  The vendor patched the vulnerability after the CVE was published.

28 Feb 2026, 01:09

Type Values Removed Values Added
CPE cpe:2.3:a:signumtte:windesk.fm:*:*:*:*:*:*:*:*
First Time Signumtte windesk.fm
Signumtte
References () https://www.usom.gov.tr/bildirim/tr-26-0085 - () https://www.usom.gov.tr/bildirim/tr-26-0085 - Third Party Advisory

27 Feb 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-27 13:16

Updated : 2026-04-16 16:16


NVD link : CVE-2025-11252

Mitre link : CVE-2025-11252

CVE.ORG link : CVE-2025-11252


JSON object : View

Products Affected

signumtte

  • windesk.fm
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')