PT-2025-13384 · Wegia · Wegia

Nmmorette

·

Published

2025-03-27

·

Updated

2025-04-10

·

CVE-2025-30364

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.2.8
Description A SQL Injection issue was identified in the "/WeGIA/html/funcionario/remuneracao.php" endpoint, specifically in the id funcionario parameter. This allows the execution of arbitrary SQL commands, potentially compromising data confidentiality, integrity, and availability.
Recommendations For versions prior to 3.2.8, update to version 3.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the "/WeGIA/html/funcionario/remuneracao.php" endpoint until the update is applied. Avoid using the id funcionario parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-30364
GHSA-X3FF-5QP7-43QV

Affected Products

Wegia