PT-2025-20285 · Wegia · Wegia

Gabrielpintosouza

+1

·

Published

2025-05-07

·

Updated

2025-07-02

·

CVE-2025-46828

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions up to and including 3.3.0
Description An unauthenticated SQL Injection issue was identified in the endpoint "/html/socio/sistema/get socios.php", specifically in the query parameter. This allows attackers to inject and execute arbitrary SQL statements against the application's underlying database, potentially leading to data exfiltration, authentication bypass, or complete database compromise.
Recommendations For versions up to and including 3.3.0, update to version 3.3.1 to fix the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint "/html/socio/sistema/get socios.php" until the update is applied.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-46828
GHSA-5QW5-Q55H-6QG7

Affected Products

Wegia