Home
CRITICAL: 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
all versions
affected
Description
SQL injection vulnerability in Bookgy. This vulnerability could allow an attacker to retrieve, create, update and delete databases by sending an HTTP request through the "IDRESERVA" parameter in /bkg_imprimir_comprobante.php
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
all versions
Credits
David Utón Amaya (m3n0sd0n4ld)
References
www.incibe.es/...tices/aviso/multiple-vulnerabilities-bookgy
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.