First published: Tue Apr 29 2025(Updated: )
Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles.
Credit: cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
Bookgy |
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-40619 is considered a high severity vulnerability due to its potential for unauthorized access to private areas of the application.
To fix CVE-2025-40619, implement proper authorization controls to ensure that users can only access areas appropriate to their roles.
CVE-2025-40619 affects multiple areas within the Bookgy application where authorization controls are insufficient.
Any user of the Bookgy application could be impacted by CVE-2025-40619 if unauthorized access to sensitive information occurs.
No, CVE-2025-40619 can be exploited without authentication, allowing malicious actors to access restricted areas.