Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

Eventobot Allows Unsecured Access to Databases

CVE-2025-40639
Summary

An attacker can use Eventobot's promo_send parameter to access, modify, or delete sensitive database information. This could expose confidential data and disrupt operations. Update Eventobot to the latest version to prevent exploitation.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
sbitsoft eventobot All versions –
Original title
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/...
Original description
A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, update and delete databases through the 'promo_send' parameter in the '/assets/php/calculate_discount.php'.
nvd CVSS4.0 8.7
Vulnerability type
CWE-89 SQL Injection
Published: 9 Mar 2026 · Updated: 13 Mar 2026 · First seen: 9 Mar 2026