Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-40715


SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo mensaje inĀ /QISClient/api/v1/sucesospaginas.


Published

2025-07-08T12:15:22.513

Last Modified

2025-10-18T01:39:23.210

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application quiter quiter_gateway < 4.7.0 Yes

References