CVE-2025-23219 Details
Description
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_cor.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sensitive information. During the exploit, it was possible to perform a complete dump of the application's database, highlighting the severity of the flaw. This vulnerability is fixed in 3.2.10.
A SQL injection vulnerability has been identified in the WeGIA application, specifically within the adicionar_cor.php endpoint. This flaw allows attackers to execute arbitrary SQL commands, leading to unauthorized access to sensitive information. Exploitation of this vulnerability enabled a complete dump of the application's database, underscoring its severity. The issue arises because the application fails to properly validate or sanitize the 'cor' parameter, allowing direct manipulation of SQL queries. This vulnerability affects WeGIA versions prior to 3.2.9.
Users can update to WeGIA version 3.2.10 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wegia wegia | < 3.2.10 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 28, 2025 | Initial Analysis | [email protected] |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 21, 2025 | CVE Modified | CISA-ADP |
| Jan 20, 2025 | New CVE Received | [email protected] |