SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bookgy
Bookgy bookgy |
|
| CPEs | cpe:2.3:a:bookgy:bookgy:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Bookgy
Bookgy bookgy |
|
| Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php. | |
| Title | SQL injection vulnerability in Bookgy | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-04-29T15:42:32.647Z
Updated: 2025-04-29T16:17:03.869Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40617
Updated: 2025-04-29T16:16:58.750Z
Status : Analyzed
Published: 2025-04-29T16:15:36.450
Modified: 2025-10-14T20:58:39.150
Link: CVE-2025-40617
No data.