SQL Injection Vulnerability in Prevengos by Nedatec Consulting
CVE-2025-40698
8.7HIGH
What is CVE-2025-40698?
An SQL injection vulnerability exists in Prevengos v2.44 developed by Nedatec Consulting. This flaw enables attackers to execute unauthorized SQL commands, potentially providing the ability to manipulate the database. By crafting a specific POST request with parameters such as 'mpsCentroin', 'mpsEmpresa', 'mpsProyecto', and 'mpsContrata', an attacker could exploit this vulnerability through the endpoint '/servicios/autorizaciones.asmx/mfsRecuperarListado'. Consequently, compromised database operations may allow unauthorized data retrieval, creation, modification, or deletion, posing a significant risk to the integrity and confidentiality of the data managed by Prevengos.
Affected Version(s)
Prevengos 0 < 2.48
References
CVSS V4
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Pedro Gabaldón Juliá
Javier Medina Munuera
Antonio José Gálvez Sánchez
Alejandro Baño Andrés
Álvaro Piñero Laorden