Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12640 | SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php |
Solution
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bookgy
Bookgy bookgy |
|
| CPEs | cpe:2.3:a:bookgy:bookgy:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Bookgy
Bookgy bookgy |
|
| Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php | |
| Title | SQL injection vulnerability in Bookgy | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-29T15:51:07.236Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40618
Updated: 2025-04-29T15:51:02.397Z
Status : Analyzed
Published: 2025-04-29T16:15:36.580
Modified: 2025-10-14T20:58:13.777
Link: CVE-2025-40618
No data.
OpenCVE Enrichment
No data.
EUVD