PT-2026-24797 · Labredescefetrj+2 · Wegia

Nilson Lazarin

·

Published

2026-03-11

·

Updated

2026-03-11

·

CVE-2026-31895

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.6
Description WeGIA is a web manager for charitable institutions. Versions of the software prior to 3.6.6 contain a SQL injection issue in the ‘html/matPat/restaurar produto.php’ file. The id produto parameter, received via the GET request, is directly used in SQL queries without proper sanitization or parameterization. This allows for potential manipulation of database queries.
Recommendations Update to version 3.6.6 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-31895
GHSA-M39R-P62F-VMQM

Affected Products

Wegia