Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the Bookgy team in October 2024 and are no longer exploitable today.
Workaround
No workaround given by the vendor.
Tue, 29 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 29 Apr 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Bookgy does not provide for proper authorisation control in multiple areas of the application. This deficiency could allow a malicious actor, without authentication, to reach private areas and/or areas intended for other roles. | |
Title | Improper access control vulnerability in Bookgy | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-04-29T16:06:37.247Z
Reserved: 2025-04-16T08:38:07.129Z
Link: CVE-2025-40619

Updated: 2025-04-29T16:06:31.318Z

Status : Awaiting Analysis
Published: 2025-04-29T16:15:36.727
Modified: 2025-05-02T13:53:40.163
Link: CVE-2025-40619

No data.

No data.