PatchSiren

Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. CVE published 2026-05-14

CVE-2025-15024

CVE-2025-15024 is a Code Injection vulnerability in the Library Automation System by Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. The issue affects versions from 19.5 to before 22.1. This vulnerability allows remote code inclusion, which could lead to system compromise, lateral movement within the network, and data tampering or unauthorized access. Defe [truncated]

HIGH Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. CVE published 2026-05-14

CVE-2025-15023

An Incorrect Authorization vulnerability exists in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System, affecting versions from 19.5 to before 22.1. This issue allows Exploiting Incorrectly Configured Access Control Security Levels. The CVSS score is 8.8, indicating a HIGH severity.

HIGH Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. CVE published 2026-05-14

CVE-2025-15025

A vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows for authorization bypass through user-controlled keys, enabling exploitation of trusted identifiers. This issue affects Library Automation System versions from 21.6 up to but not including 22.1. The vulnerability's high severity, with a CVSS score of 8.8, em [truncated]