Unrated severityNVD Advisory· Published Jul 8, 2025· Updated Aug 7, 2025
SQL injection vulnerability in Quiter Gateway
CVE-2025-40712
Description
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the id_concesion parameter in /FacturaE/DescargarFactura.
Affected products
2- Range: <4.7.0
- Quiter/Quiter Gateway (Java WAR on Apache Tomcat)v5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.