Bookgy SQL Injection Vulnerability in bkg_imprimir_comprobante.php

Vulnerability

A SQL injection vulnerability has been identified in Bookgy, an online booking and management software. This vulnerability allows attackers to retrieve, create, update, and delete databases by sending an HTTP request through the 'IDRESERVA' parameter in the 'bkg_imprimir_comprobante.php' file.

Impact

Exploitation of this vulnerability could lead to unauthorized database manipulation, allowing attackers to alter, delete, or extract sensitive information from the database.

Remediation

The Bookgy team has fixed this vulnerability, and it is no longer exploitable.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.