First published: Tue Apr 29 2025(Updated: )
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Bookgy |
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40618 is classified as a high severity SQL injection vulnerability.
Fix CVE-2025-40618 by validating and sanitizing the input from the "IDRESERVA" parameter to prevent unauthorized database access.
CVE-2025-40618 can facilitate attacks that allow an attacker to retrieve, create, update, and delete databases.
CVE-2025-40618 is found in the Bookgy software.
The "IDRESERVA" parameter in the /bkg_imprimir_comprobante.php file is vulnerable in CVE-2025-40618.