SQL Injection Vulnerability in Prevengos by Nedatec Consulting
CVE-2025-40698
What is CVE-2025-40698?
An SQL injection vulnerability exists in Prevengos v2.44 developed by Nedatec Consulting. This flaw enables attackers to execute unauthorized SQL commands, potentially providing the ability to manipulate the database. By crafting a specific POST request with parameters such as 'mpsCentroin', 'mpsEmpresa', 'mpsProyecto', and 'mpsContrata', an attacker could exploit this vulnerability through the endpoint '/servicios/autorizaciones.asmx/mfsRecuperarListado'. Consequently, compromised database operations may allow unauthorized data retrieval, creation, modification, or deletion, posing a significant risk to the integrity and confidentiality of the data managed by Prevengos.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Prevengos 0 < 2.48
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
