PT-2026-28585 · Wegia · Wegia

Ormzro

·

Publicado

2026-03-27

·

Atualizado

2026-03-28

·

CVE-2026-33991

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.7
Description WeGIA is a web manager for charitable institutions. Versions prior to 3.6.7 contain a flaw in the html/socio/sistema/deletar tag.php file. This file utilizes the extract($ REQUEST) function on line 14, and the $id tag variable is directly concatenated into SQL queries on lines 16-17 without employing prepared statements or sanitization. This can lead to SQL injection.
Recommendations Update to WeGIA version 3.6.7 or later.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33991
GHSA-74XM-6WGF-X37J

Produtos afetados

Wegia