PT-2025-29914 · Wegia · Wegia

Marcelomulder

+1

·

Published

2025-07-13

·

Updated

2025-07-17

·

CVE-2025-53946

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open source web manager. A SQL Injection vulnerability exists due to manipulation of SQL queries through the id funcionario parameter of the /html/saude/profile paciente.php endpoint, potentially allowing access to sensitive database information.
Recommendations Update WeGIA to version 3.4.5 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09399
CVE-2025-53946
GHSA-532R-MGXV-G7JM

Affected Products

Wegia