CVE-2025-40635 Information
May 21, 2025
cve
Description
SQL injection vulnerability in Comerzzia Backoffice: Sales Orchestrator 3.0.15. This vulnerability allows an attacker to retrieve create update and delete databases via the ‘uidActivity’ ‘codCompany’ and ‘uidInstance’ parameters of the ‘/comerzzia/login’ endpoint.
Reference
https://www.incibe.es/en/incibe-cert/notices/aviso/sql-injection-comerzzia
Share on: