Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-12649 | Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles. |
Solution
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Workaround
No workaround given by the vendor.
Tue, 14 Oct 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Bookgy
Bookgy bookgy |
|
CPEs | cpe:2.3:a:bookgy:bookgy:-:*:*:*:*:*:*:* | |
Vendors & Products |
Bookgy
Bookgy bookgy |
|
Metrics |
cvssV3_1
|
Tue, 29 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles. | |
Title | Improper access control vulnerability in Bookgy | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-29T16:06:37.247Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40619

Updated: 2025-04-29T16:06:31.318Z

Status : Analyzed
Published: 2025-04-29T16:15:36.727
Modified: 2025-10-14T20:56:49.757
Link: CVE-2025-40619

No data.

No data.