PT-2025-28217 · Wegia · Wegia

·

CVE-2025-53527

·

Published

2025-07-07

·

Updated

2025-07-07

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.1
Description: A Time-Based Blind SQL Injection issue was discovered in the almox parameter of the "/controle/relatorio geracao.php" endpoint. This allows an attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on the database configuration.
Recommendations: For versions prior to 3.4.1, update to version 3.4.1 to resolve the issue. As a temporary workaround, consider restricting access to the "/controle/relatorio geracao.php" endpoint or limiting the use of the almox parameter to minimize the risk of exploitation.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-53527
GHSA-43XW-C4G6-JGFF

Affected Products

Wegia