Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-12643 | Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php. |
Solution
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bookgy
Bookgy bookgy |
|
CPEs | cpe:2.3:a:bookgy:bookgy:-:*:*:*:*:*:*:* | |
Vendors & Products |
Bookgy
Bookgy bookgy |
|
Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending a malicious URL through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php. | |
Title | Reflected Cross-Site Scripting (XSS) vulnerability in Bookgy | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-29T16:20:16.950Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40616

Updated: 2025-04-29T16:20:13.024Z

Status : Analyzed
Published: 2025-04-29T16:15:36.310
Modified: 2025-10-14T20:58:53.150
Link: CVE-2025-40616

No data.

No data.