CVE-2025-40712

All FrameworksApache TomcatCWE-89CVE-2025-40712

CVE-2025-40712

State: PUBLISHED · Published: 2025-07-08 · Updated: 2025-08-07 · Assigner: INCIBE
Description
SQL injection vulnerability in versions prior to 4.7.0 of Quiter Gateway by Quiter. This vulnerability allows an attacker to retrieve, create, update and delete databases through the id_concesion parameter in /<Client>FacturaE/DescargarFactura.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2025/40xxx/CVE-2025-40712.json