SQL Injection Vulnerability in Prevengos by Nedatec Consulting
CVE-2025-40698

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
25 September 2025

What is CVE-2025-40698?

An SQL injection vulnerability exists in Prevengos v2.44 developed by Nedatec Consulting. This flaw enables attackers to execute unauthorized SQL commands, potentially providing the ability to manipulate the database. By crafting a specific POST request with parameters such as 'mpsCentroin', 'mpsEmpresa', 'mpsProyecto', and 'mpsContrata', an attacker could exploit this vulnerability through the endpoint '/servicios/autorizaciones.asmx/mfsRecuperarListado'. Consequently, compromised database operations may allow unauthorized data retrieval, creation, modification, or deletion, posing a significant risk to the integrity and confidentiality of the data managed by Prevengos.

Affected Version(s)

Prevengos 0 < 2.48

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pedro Gabaldón Juliá
Javier Medina Munuera
Antonio José Gálvez Sánchez
Alejandro Baño Andrés
Álvaro Piñero Laorden
.
CVE-2025-40698 : SQL Injection Vulnerability in Prevengos by Nedatec Consulting