PT-2025-20285 · Wegia · Wegia
Gabrielpintosouza
+1
·
Published
2025-05-07
·
Updated
2025-07-02
·
CVE-2025-46828
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
WeGIA versions up to and including 3.3.0
Description
An unauthenticated SQL Injection issue was identified in the endpoint "/html/socio/sistema/get socios.php", specifically in the query parameter. This allows attackers to inject and execute arbitrary SQL statements against the application's underlying database, potentially leading to data exfiltration, authentication bypass, or complete database compromise.
Recommendations
For versions up to and including 3.3.0, update to version 3.3.1 to fix the issue.
As a temporary workaround, consider restricting access to the vulnerable endpoint "/html/socio/sistema/get socios.php" until the update is applied.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia