Summar Employee Portal 3.98.0 – Authenticated SQL Injection
# Exploit Title: Summar Employee Portal 3.98.0 – Authenticated SQL Injection # Google Dork: inurl:”/MemberPages/quienesquien.aspx” # Date: 09/22/2025 # Exploit Author: Peter Gabaldon – https://pgj11.com/ # Vendor Homepage: https://www.summar.es/ # Software Link: https://www.summar.es/software-recursos-humanos/ # Version: < 3.98.0 # Tested on: Kali # CVE: CVE-2025-40677 # Description: SQL injection vulnerability in Summar Software´s Portal del Empleado….


