PT-2025-29866 · Wegia · Wegia

Marcelomulder

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53937

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open-source web manager designed for Portuguese-language and charitable institutions. A SQL Injection issue exists in the /controle/control.php API endpoint, specifically through the cargo parameter. This allows attackers to execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability.
Recommendations Update to WeGIA version 3.4.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09271
CVE-2025-53937
GHSA-J3QV-V3M7-73PJ

Affected Products

Wegia