A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.

Project Subscriptions

Vendors Products
Eventobot Subscribe
Eventobot Subscribe
Sbitsoft Subscribe
Eventobot Subscribe
Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by the Eventobot team in the latest version.


Workaround

No workaround given by the vendor.

History

Tue, 10 Mar 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Sbitsoft
Sbitsoft eventobot
CPEs cpe:2.3:a:sbitsoft:eventobot:-:*:*:*:*:*:*:*
Vendors & Products Sbitsoft
Sbitsoft eventobot
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 09 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 09 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
Description A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.
Title SQL injection in Eventobot
First Time appeared Eventobot
Eventobot eventobot
Weaknesses CWE-89
CPEs cpe:2.3:a:eventobot:eventobot:all_versions:*:*:*:*:*:*:*
Vendors & Products Eventobot
Eventobot eventobot
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-03-09T20:05:09.804Z

Reserved: 2025-04-16T08:38:10.819Z

Link: CVE-2025-40639

cve-icon Vulnrichment

Updated: 2026-03-09T20:05:06.971Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-09T10:16:01.017

Modified: 2026-03-10T19:56:35.940

Link: CVE-2025-40639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-10T14:07:37Z

Weaknesses