PT-2025-40424 · Wegia · Wegia

Marcelomulder

·

Published

2025-10-02

·

Updated

2025-10-07

·

CVE-2025-61603

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.4.12 and below
Description WeGIA is a Web manager for charitable institutions. A SQL Injection issue exists in the /controle/control.php endpoint, specifically in the descricao parameter. This allows attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of the database.
Recommendations Update to version 3.5.0 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-61603
GHSA-V8HM-PQ8G-C7J4

Affected Products

Wegia