CNNVD-202509-4274 Information
Sep 27, 2025
cve
CNNVD ID
CNNVD-202509-4274
Related CVE
- CNNVD Published: 2025-09-27
Description (Chinese)
WeGIA是Nilson Lazarin个人开发者的一个福利机构的网络管理器。 WeGIA 3.5.0之前版本存在SQL注入漏洞,该漏洞源于对control.php端点中id_produto参数处理不当,可能导致SQL注入攻击。
Description (English)
WeGIA is the network manager of a welfare institution of the Nelson Lazarin personal developer. The previous version of Wegia 3.5.0 had an injection loophole in SQL, which stemmed from the mishandling of id produto parameters at the control.php endpoint, which could lead to an attack on SQL.
Hazard Level
Medium
Vulnerability Type
SQL注入
Affected Vendor
个人开发者
Published
2025-09-27
Last Modified
2026-02-24
References
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jx9m-pgf8-v489 https://access.redhat.com/security/cve/cve-2025-59939
Patch
https://github.com/LabRedesCefetRJ/WeGIA/releases
Share on: