PT-2025-30059 · Wegia · Wegia

Whyrusx

·

Published

2025-07-17

·

Updated

2025-07-18

·

CVE-2025-54079

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.6
Description WeGIA is an open source web manager. A SQL Injection vulnerability exists in the /html/atendido/Profile Atendido.php endpoint, specifically in the idatendido parameter. This allows an attacker to execute arbitrary SQL queries and potentially access sensitive information.
Recommendations Update WeGIA to version 3.4.6 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-09398
CVE-2025-54079
GHSA-G4V3-J8W5-33V3

Affected Products

Wegia