9.8
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics Yordam Library Automation System allows SQL Injection.This issue affects Yordam Library Automation System: from 21.5 & 21.6 before 21.7.
Basic Information
ID
CVE-2025-10439
Source
TR-CERT
Published
Sep 17, 2025 at 11:45
Affected Product
Vendor
Yordam Informatics
Product
Yordam Library Automation System
Version
21.5 & 21.6
Affected Versions
Yordam Informatics Yordam Library Automation System 21.5 & 21.6