CVE-2025-26852
CVSS 3.1 Score 10 of 10 (high)
Details
Published Mar 20, 2025
Updated: Apr 3, 2025
CWE ID 89
Summary
CVE-2025-26852 is a newly identified vulnerability affecting DESCor INFOCAD versions 3.5.1 and prior. This issue allows SQL injection attacks, which can enable unauthorized users to access or manipulate sensitive data within the system. The vulnerability was addressed in version 3.5.2.0 with a fix. SQL injection attacks can lead to significant data breaches, making this a critical security concern for organizations using INFOCAD software. It is advised that affected users upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.