Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by Quiter team in the latest version.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20461 | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the suceso.contenido mensaje in /QMSCliente/Sucesos.action. |
Sat, 18 Oct 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quiter
Quiter quiter Gateway |
|
| CPEs | cpe:2.3:a:quiter:quiter_gateway:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Quiter
Quiter quiter Gateway |
|
| Metrics |
cvssV3_1
|
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the suceso.contenido mensaje in /QMSCliente/Sucesos.action. | |
| Title | SQL injection vulnerability in Quiter Gateway | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-07-10T10:13:38.804Z
Reserved: 2025-04-16T08:38:20.492Z
Link: CVE-2025-40716
Updated: 2025-07-08T15:59:27.720Z
Status : Analyzed
Published: 2025-07-08T12:15:22.660
Modified: 2025-10-18T01:38:12.793
Link: CVE-2025-40716
No data.
OpenCVE Enrichment
No data.
EUVD