Unrated severityNVD Advisory· Published Apr 29, 2025· Updated Apr 29, 2025
SQL injection vulnerability in Bookgy
CVE-2025-40617
Description
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDTIPO", "IDPISTA" and "IDSOCIO" parameters in /bkg_seleccionar_hora_ajax.php.
Affected products
2- Bookgy/Bookgyv5Range: all versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.