ATISoluciones Ciges SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability exists in Ciges version 2.15.5, allowing attackers to manipulate the database through the $idServicio parameter in the /modules/ajaxBloqueaCita.php endpoint. This exploitation could involve retrieving, creating, updating, or deleting database records.

Impact

Exploitation of this vulnerability allows for unauthorized database manipulation, including retrieval, creation, updating, and deletion of records.

Remediation

Users can upgrade to Ciges version 2.15.6 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.