WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
References
Link | Resource |
---|---|
https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 | Exploit Vendor Advisory |
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 | Exploit Vendor Advisory |
Configurations
History
09 Apr 2025, 18:28
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wegia
Wegia wegia |
|
Summary |
|
|
CPE | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 - Exploit, Vendor Advisory | |
References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 - Exploit, Vendor Advisory |
08 Jan 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 Jan 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-08 19:15
Updated : 2025-04-09 18:28
NVD link : CVE-2025-22141
Mitre link : CVE-2025-22141
CVE.ORG link : CVE-2025-22141
JSON object : View
Products Affected
wegia
- wegia
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')