PT-2025-40426 · Wegia · Wegia

Marcelomulder

·

Published

2025-10-02

·

Updated

2025-10-07

·

CVE-2025-61605

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.4.12 and below
Description WeGIA is an open source web manager designed for charitable institutions. A SQL Injection issue exists in the id pet parameter of the '/pet/profile pet.php' API endpoint. This allows attackers to execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability. The issue allows for full database takeover with low privileges.
Recommendations Update to version 3.5.0 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-61605
GHSA-8963-9833-GPX7

Affected Products

Wegia