CVE-2025-40639: SQL Injection

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the ‘promo_send’ parameter in the ‘/assets/php/calculate_discount.php

CVECVE-2025-40639
CVSSv39.8
Published Date9 March 2026
ExploitationNone
ImpactNot applicable

Solution:

Eventbot team has been fix this vulnerability.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *