PT-2025-29917 · Wegia · Wegia

Marcelomulder

·

Published

2025-07-17

·

Updated

2025-07-17

·

CVE-2025-54061

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.6
Description WeGIA is an open source web manager. A SQL Injection vulnerability exists in the idatendido familiares parameter of the /html/funcionario/dependente editarDoc.php endpoint. This allows manipulation of SQL queries and potential access to sensitive database information.
Recommendations Update WeGIA to version 3.4.6 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-09400
CVE-2025-54061
GHSA-G47Q-VFPJ-G9MR

Affected Products

Wegia