PT-2025-28219 · Wegia · Wegia

Pedro-Lyrio

·

Published

2025-07-07

·

Updated

2025-07-07

·

CVE-2025-53529

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.3
Description: A critical issue was identified in WeGIA, a web manager for charitable institutions. The /html/funcionario/profile funcionario.php endpoint is vulnerable due to the id funcionario parameter not being properly sanitized or validated before being used in a SQL query. This allows an unauthenticated attacker to inject arbitrary SQL commands.
Recommendations: For versions prior to 3.4.3, update to version 3.4.3 to resolve the issue. As a temporary workaround, consider restricting access to the /html/funcionario/profile funcionario.php endpoint until the update is applied. Additionally, avoid using the id funcionario parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-53529
GHSA-RRJ6-PJ6W-8J2R

Affected Products

Wegia