CVE-2025-40677: Summar Software Portal Del Empleado
High severity, CVSS 8.7. EPSS: 0.6% chance of exploitation in the next 30 days.
SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve, create, update, and delete the database by sending a POST request using the parameter “ctl00$ContentPlaceHolder1$filtroNombre” in “/MemberPages/quienesquien.aspx”.
Affected products
- Summar Software Portal Del Empleado: version 3.98.0 only
Published 2025-09-18. Last modified 2026-06-17.