CVE-2025-40617
Severity CVSS v4.0:
CRITICAL
Type:
CWE-89
SQL Injection
Publication date:
29/04/2025
Last modified:
02/05/2025
Description
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php.
Impact
Base Score 4.0
9.30
Severity 4.0
CRITICAL