Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Quiter team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20463 | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo id_factura in /<Client>FacturaE/listado_facturas_ficha.jsp. |
Wed, 15 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quiter
Quiter quiter Gateway |
|
| CPEs | cpe:2.3:a:quiter:quiter_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quiter
Quiter quiter Gateway |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo id_factura in /<Client>FacturaE/listado_facturas_ficha.jsp. | |
| Title | SQL injection vulnerability in Quiter Gateway | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-10T10:13:15.911Z
Reserved: 2025-04-16T08:38:19.332Z
Link: CVE-2025-40714
Updated: 2025-07-08T19:19:43.433Z
Status : Analyzed
Published: 2025-07-08T12:15:22.367
Modified: 2025-10-15T19:20:03.270
Link: CVE-2025-40714
No data.
OpenCVE Enrichment
No data.
EUVD