CVE-2025-22141 Information
Jan 09, 2025
cve
Description
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands compromising the confidentiality integrity and availability of the database. This vulnerability is fixed in 3.2.8.
Reference
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636 https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-w7hp-2w2c-p636
Share on: