PT-2025-41821 · Wegia · Wegia

Hungxqt

·

Published

2025-10-13

·

Updated

2025-10-20

·

CVE-2025-62360

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.5.1
Description WeGIA is a Web Manager for Institutions. A SQL Injection issue exists in the /html/funcionario/dependente documento.php API endpoint, specifically through the id dependente parameter. Successful exploitation allows attackers to execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability.
Recommendations Update to version 3.5.1 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-62360
GHSA-M4J6-Q5M4-X24G
GHSA-MWVV-Q9GH-GWXM

Affected Products

Wegia