Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5319 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. |
Solution
All functions involved in ajaxBloqueoCita.php are reviewed, and some queries that cause this vulnerability are found. Prepared statements are then implemented in all of them. A new version of the software, v2.15.6, has been released to address the detected vulnerabilities.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.atisoluciones.com/incidentes-cve |
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. | |
| Title | SQL Injection CIGES | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ATIS
Published:
Updated: 2025-02-27T14:42:34.087Z
Reserved: 2025-02-27T11:17:37.585Z
Link: CVE-2025-1751
Updated: 2025-02-27T14:42:27.698Z
Status : Received
Published: 2025-02-27T12:15:35.030
Modified: 2025-02-27T12:15:35.030
Link: CVE-2025-1751
No data.
OpenCVE Enrichment
No data.
EUVD