CVE-2025-40639 | Eventobot calculate_discount.php promo_send sql injection (EUVD-2025-208400)
A vulnerability was found in Eventobot. It has been classified as critical. The affected element is an unknown function of the file /assets/php/calculate_discount.php. This manipulation of the argument promo_send causes sql injection.
This vulnerability is registered as CVE-2025-40639. Remote exploitation of the attack is possible. No exploit is available.