PT-2025-28217 · Wegia · Wegia

Nmmorette

·

Published

2025-07-07

·

Updated

2025-07-07

·

CVE-2025-53527

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.1
Description: A Time-Based Blind SQL Injection issue was discovered in the almox parameter of the "/controle/relatorio geracao.php" endpoint. This allows an attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on the database configuration.
Recommendations: For versions prior to 3.4.1, update to version 3.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the "/controle/relatorio geracao.php" endpoint or limiting the use of the almox parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-53527
GHSA-43XW-C4G6-JGFF

Affected Products

Wegia