CVE-2025-40639

Eventobot - SQL Injection

Title source: llm

Description

A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.

Scores

EPSS 0.0003
EPSS Percentile 8.3%

Classification

CWE
CWE-89
Status draft

Timeline

Published Mar 09, 2026
Tracked Since Mar 09, 2026