Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Workaround
No workaround given by the vendor.
Tue, 29 Apr 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php. | |
Title | SQL injection vulnerability in Bookgy | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-29T16:17:03.869Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40617

Updated: 2025-04-29T16:16:58.750Z

Status : Awaiting Analysis
Published: 2025-04-29T16:15:36.450
Modified: 2025-05-02T13:53:40.163
Link: CVE-2025-40617

No data.

No data.