PT-2025-41817 · Wegia · Wegia

Thevietronin

·

Published

2025-10-13

·

Updated

2025-10-20

·

CVE-2025-62179

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.5.1
Description WeGIA is a Web Manager for Institutions. A SQL Injection issue exists in the /html/funcionario/cadastro funcionario pessoa existente.php API endpoint, specifically affecting the cpf parameter. Successful exploitation allows attackers to execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability.
Recommendations Update to version 3.5.1 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62179
GHSA-X36X-X5J4-WFJF

Affected Products

Wegia