PT-2025-20073 · Lemeconsultoria · Galera.App

Published

2025-05-07

·

Updated

2025-07-09

·

CVE-2025-29153

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions lemeconsultoria HCM galera.app version 4.58.0
Description The issue allows an attacker to execute arbitrary code via the Data export and filters functions. This is due to a SQL Injection vulnerability.
Recommendations For version 4.58.0, update to a version that fixes this issue, as the current version allows for the execution of arbitrary code, posing a significant security risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-29153

Affected Products

Galera.App