PT-2026-33513 · Wegia · Wegia
Published
2026-04-17
·
Updated
2026-04-21
·
CVE-2026-40285
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WeGIA versions prior to 3.6.10
Description
An issue exists in the
dao/memorando/UsuarioDAO.php file where the cpf usuario POST parameter overwrites the session-stored user identity through the extract($ REQUEST) function in DespachoControle::verificarDespacho(). This attacker-controlled value is interpolated directly into a raw SQL query, enabling any authenticated user to query the database using an arbitrary identity.Recommendations
Update to version 3.6.10.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wegia