CVE-2025-22141 Information

Description

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands compromising the confidentiality integrity and availability of the database. This vulnerability is fixed in 3.2.8.

Reference

https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636

Share on: