Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Quiter team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20462 | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo mensaje in /QISClient/api/v1/sucesospaginas. |
Sat, 18 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quiter
Quiter quiter Gateway |
|
| CPEs | cpe:2.3:a:quiter:quiter_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quiter
Quiter quiter Gateway |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the campo mensaje in /QISClient/api/v1/sucesospaginas. | |
| Title | SQL injection vulnerability in Quiter Gateway | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-10T10:13:26.518Z
Reserved: 2025-04-16T08:38:20.492Z
Link: CVE-2025-40715
Updated: 2025-07-08T16:03:58.745Z
Status : Analyzed
Published: 2025-07-08T12:15:22.513
Modified: 2025-10-18T01:39:23.210
Link: CVE-2025-40715
No data.
OpenCVE Enrichment
No data.
EUVD