CVE-2025-1751

A SQL Injection vulnerability has been found in Ciges 2.15.5 from ATISoluciones. This vulnerability allows an attacker to retrieve, create, update and delete database via $idServicio parameter in /modules/ajaxBloqueaCita.php endpoint.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad de inyección SQL en Ciges 2.15.5 de ATISoluciones. Esta vulnerabilidad permite a un atacante recuperar, crear, actualizar y eliminar una base de datos a través del parámetro $idServicio en el endpoint /modules/ajaxBloqueaCita.php.

27 Feb 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-27 12:15

Updated : 2026-06-17 08:39


NVD link : CVE-2025-1751

Mitre link : CVE-2025-1751

CVE.ORG link : CVE-2025-1751


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')