CVE-2024-57034 Details
Description
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
A SQL injection vulnerability exists in WeGIA versions prior to 3.2.0, specifically in the query_geracao_auto.php file. The vulnerability allows attackers to manipulate the query parameter and execute arbitrary SQL commands, potentially compromising the database's confidentiality, integrity, and availability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nmmorette/vulnerability-research/tree/main/CVE-2024-57034 | [email protected] | ExploitThird Party Advisory |
| https://www.wegia.org | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| wegia wegia | < 3.2.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 14, 2025 | CVE Modified | CISA-ADP |
| Feb 28, 2025 | Initial Analysis | [email protected] |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 21, 2025 | CVE Modified | CISA-ADP |
| Jan 17, 2025 | New CVE Received | [email protected] |