Beveiligingsadvies

CVE-2025-40671

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-05-26 09:08:05
Laatst bijgewerkt 2025-06-04 09:56:16
Toegewezen door INCIBE
CVSS-score 9.3
Status PUBLISHED

Beschrijving

SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create, update and delete databases via the ‘fk_remoto_central’ parameter on the ‘/webservices/articles.php’ endpoint.