A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the ‘promo_send’ parameter in the ‘/assets/php/calculate_discount.php‘
| CVE | CVE-2025-40639 |
| CVSSv3 | 9.8 |
| Published Date | 9 March 2026 |
| Exploitation | None |
| Impact | Not applicable |
Solution:
Eventbot team has been fix this vulnerability.


Leave a Reply