PT-2025-4377 · Wegia · Wegia

Lislovelly

+1

·

Published

2025-01-08

·

Updated

2025-01-08

·

CVE-2025-22141

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.2.8
Description A SQL Injection vulnerability was identified in the "/dao/verificar recursos cargo.php" endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database.
Recommendations For versions prior to 3.2.8, update to version 3.2.8 to resolve the issue. As a temporary workaround, consider restricting access to the "/dao/verificar recursos cargo.php" endpoint until the update is applied. Avoid using the cargo parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2025-22141
GHSA-W7HP-2W2C-P636

Affected Products

Wegia