Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnreability has been fixed by the Nedatec Consulting team in version 2.48 of the application's web portal, released on 18/11/2024.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-31078 | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”. |
Thu, 25 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 25 Sep 2025 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in Prevengos v2.44 by Nedatec Consulting. This vulnerability allows an attacker to retrieve, create, update, and delete databases by sending a POST request using the parameters “mpsCentroin”, “mpsEmpresa”, “mpsProyecto”, and “mpsContrata” in “/servicios/autorizaciones.asmx/mfsRecuperarListado”. | |
| Title | SQL injection vulnerability in Prevengos | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-09-25T13:12:10.920Z
Reserved: 2025-04-16T08:38:18.261Z
Link: CVE-2025-40698
Updated: 2025-09-25T13:12:07.582Z
Status : Deferred
Published: 2025-09-25T12:15:30.760
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40698
No data.
OpenCVE Enrichment
No data.
EUVD