PT-2025-8934 · Ciges · Ciges

Published

2025-02-27

·

Updated

2025-02-27

·

CVE-2025-1751

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ciges version 2.15.5
Description A SQL Injection issue has been discovered, allowing an attacker to manipulate the database by exploiting the $idServicio parameter in the "/modules/ajaxBloqueaCita.php" endpoint. This enables unauthorized retrieval, creation, update, and deletion of database content.
Recommendations For Ciges version 2.15.5, consider restricting access to the "/modules/ajaxBloqueaCita.php" endpoint until a fix is available, and avoid using the $idServicio parameter in this endpoint to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1751

Affected Products

Ciges