SQL Injection Vulnerability in Quiter Gateway by Quiter
CVE-2025-40717
9.3CRITICAL
What is CVE-2025-40717?
A SQL injection vulnerability exists in Quiter Gateway prior to version 4.7.0, allowing unauthorized access to the database. This weakness enables attackers to execute a series of commands that can manipulate, retrieve, create, update, or delete sensitive database information through the vulnerable endpoint located at /QuiterGatewayWeb/api/v1/sucesospagina. This issue highlights the need for robust input validation and security measures to protect against database-level attacks.
Affected Version(s)
Quiter Gateway (Java WAR on Apache Tomcat) 0 < 4.7.0