Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40618


SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA"  parameter in /bkg_imprimir_comprobante.php


Published

2025-04-29T16:15:36.580

Last Modified

2025-10-14T20:58:13.777

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bookgy bookgy - Yes

References