Metrics
Affected Vendors & Products
Solution
The vulnerability has been fixed by the Comerzzia team in version 3.1.0, released on 31 May 2016.
Workaround
No workaround given by the vendor.
Tue, 20 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 20 May 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘uidActivity’, ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint. | |
Title | SQL injection at Comerzzia | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-05-21T11:17:30.680Z
Reserved: 2025-04-16T08:38:10.818Z
Link: CVE-2025-40635

Updated: 2025-05-20T14:55:43.728Z

Status : Awaiting Analysis
Published: 2025-05-20T13:15:47.300
Modified: 2025-05-21T20:25:16.407
Link: CVE-2025-40635

No data.

No data.