Junglewise Threat Intelligence

CVE-2025-41008: Sinturno SQL injection in modalReport_data.php

CVE-2025-41008 · Severity: info · CVSS 9.3 · Published 2026-03-23

Executive brief

Sinturno, an online appointment management system, contains a critical security flaw that allows unauthorized individuals to access its database. An attacker could use this vulnerability to view, modify, or delete sensitive appointment data and customer information. This could lead to a total loss of data integrity and significant operational disruption for businesses relying on the system.

Technical details

A SQL injection vulnerability exists in Sinturno's '/_adm/scripts/modalReport_data.php' endpoint due to improper neutralization of the 'client' parameter. An unauthenticated remote attacker can exploit this by sending specially crafted SQL commands to the server. Successful exploitation allows for full CRUD (Create, Read, Update, Delete) operations on the underlying database. This vulnerability is classified as CWE-89 and has been assigned a CVSS v4.0 score of 9.3. As of the advisory date, no official patch or solution has been released.

Affected products

  • Sinturno Sinturno

Timeline

  • 2026-03-23: disclosed: Vulnerability coordinated by INCIBE and discovered by Gonzalo Aguilar García.
  • 2026-03-23: advisory: NVD and INCIBE published the advisory.

References