ATISoluciones Ciges SQL Injection Vulnerability
Vulnerability
A SQL injection vulnerability exists in Ciges version 2.15.5, allowing attackers to manipulate the database through the $idServicio parameter in the /modules/ajaxBloqueaCita.php endpoint. This exploitation could involve retrieving, creating, updating, or deleting database records.
Impact
Exploitation of this vulnerability allows for unauthorized database manipulation, including retrieval, creation, updating, and deletion of records.
Remediation
Users can upgrade to Ciges version 2.15.6 to address this vulnerability.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
3.1exploitability
7.4remediation
7.7relevance
0.0threat
0.0urgency
2.9incentive
5.8Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
