SQL Injection Vulnerability in Quiter Gateway by Quiter
CVE-2025-40713
9.3CRITICAL
What is CVE-2025-40713?
A SQL injection vulnerability exists in Quiter Gateway, affecting versions prior to 4.7.0. The flaw allows attackers to exploit the 'campo' parameter within the /FacturaE/BusquedasFacturasSesion endpoint. This exploitation can lead to unauthorized retrieval, creation, updating, and deletion of database entries, posing significant risks to data integrity and security.
Affected Version(s)
Quiter Gateway (Java WAR on Apache Tomcat) 0 < 4.7.0