PT-2026-26605 · Wegia · Wegia
Bao190505
·
Published
2026-03-20
·
Updated
2026-03-22
·
CVE-2026-33134
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WeGIA versions 3.6.5 and below
Description
WeGIA is a web manager for charitable institutions. An authenticated SQL Injection issue exists in the
/html/matPat/restaurar produto.php API endpoint. An attacker with valid credentials can inject arbitrary SQL commands through the id produto GET parameter, potentially leading to complete database compromise. The application directly retrieves the id produto parameter from the $ GET global array and incorporates it into SQL query strings without proper sanitization or the use of parameterized statements.Recommendations
Versions prior to 3.6.6 should be updated to version 3.6.6 or later.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia