CVE-2025-40617

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
29/04/2025
Last modified:
02/05/2025

Description

SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php.