Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
All functions involved in ajaxBloqueoCita.php are reviewed, and some queries that cause this vulnerability are found. Prepared statements are then implemented in all of them. A new version of the software, v2.15.6, has been released to address the detected vulnerabilities.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-5319 | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. |
| Link | Providers |
|---|---|
| https://www.atisoluciones.com/incidentes-cve |
|
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Feb 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint. | |
| Title | SQL Injection CIGES | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: ATIS
Published:
Updated: 2025-02-27T14:42:34.087Z
Reserved: 2025-02-27T11:17:37.585Z
Link: CVE-2025-1751
Updated: 2025-02-27T14:42:27.698Z
Status : Deferred
Published: 2025-02-27T12:15:35.030
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1751
No data.
OpenCVE Enrichment
No data.
EUVD