PT-2025-28412 · Unknown · Quiter Gateway
CVE-2025-40717
·
Publicado
2025-07-08
·
Atualizado
2025-10-18
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Quiter Gateway versions prior to 4.7.0
Description:
The issue allows an attacker to retrieve, create, update, and delete databases through the "pagina.filter.categoria mensaje" in the "/QuiterGatewayWeb/api/v1/sucesospagina" endpoint. This enables manipulation of databases, posing a significant risk.
Recommendations:
For versions prior to 4.7.0, update to version 4.7.0 or later to secure your system.
As a temporary workaround, consider restricting access to the "/QuiterGatewayWeb/api/v1/sucesospagina" endpoint until the issue is resolved.
Avoid using the
pagina.filter.categoria mensaje parameter in the affected API endpoint until the issue is resolved.Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Quiter Gateway