PT-2025-4858 · Wegia · Wegia

Lislovelly

·

Publicado

2025-01-20

·

Atualizado

2025-01-21

·

CVE-2025-23220

CVSS v4.0

10

Crítica

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.2.10
Description A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar raca.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sensitive information. During the exploit, it was possible to perform a complete dump of the application's database, highlighting the severity of the flaw.
Recommendations For versions prior to 3.2.10, update to version 3.2.10 to resolve the issue. As a temporary workaround, consider restricting access to the adicionar raca.php endpoint until the update is applied.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-23220
GHSA-425J-H4CF-G52J

Produtos afetados

Wegia