First published: Tue Apr 29 2025(Updated: )
Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Bookgy |
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40616 is categorized as a high-severity vulnerability due to its ability to execute arbitrary JavaScript in a user's browser.
To mitigate CVE-2025-40616, validate and sanitize all user inputs to prevent injection of malicious scripts.
CVE-2025-40616 is a reflected cross-site scripting (XSS) vulnerability.
CVE-2025-40616 occurs in the Bookgy application, specifically through the 'IDRESERVA' parameter in the /bkg_imprimir_comprobante.php endpoint.
Yes, if your website uses the vulnerable version of Bookgy and allows unsanitized inputs, it can be exploited through CVE-2025-40616.