Project Subscriptions
No advisories yet.
Solution
The vulnerability has been fixed by the Eventobot team in the latest version.
Workaround
No workaround given by the vendor.
Tue, 10 Mar 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sbitsoft
Sbitsoft eventobot |
|
| CPEs | cpe:2.3:a:sbitsoft:eventobot:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Sbitsoft
Sbitsoft eventobot |
|
| Metrics |
cvssV3_1
|
Mon, 09 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'. | |
| Title | SQL injection in Eventobot | |
| First Time appeared |
Eventobot
Eventobot eventobot |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:eventobot:eventobot:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Eventobot
Eventobot eventobot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-09T20:05:09.804Z
Reserved: 2025-04-16T08:38:10.819Z
Link: CVE-2025-40639
Updated: 2026-03-09T20:05:06.971Z
Status : Analyzed
Published: 2026-03-09T10:16:01.017
Modified: 2026-03-10T19:56:35.940
Link: CVE-2025-40639
No data.
OpenCVE Enrichment
Updated: 2026-03-10T14:07:37Z