PT-2026-3307 · Wegia · Wegia

Vinicastro2001

·

Published

2026-01-16

·

Updated

2026-01-17

·

CVE-2026-23723

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.2
Description WeGIA is a web manager for charitable institutions. A SQL Injection issue exists that allows for full database exfiltration, exposure of sensitive PII, and potential arbitrary file reads in misconfigured environments. The issue is present in the Atendido ocorrenciaControle API endpoint through the id memorando parameter and requires authentication.
Recommendations Update to version 3.6.2 or later.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-23723
GHSA-XFMP-2HF9-GFJP

Affected Products

Wegia