CVE-2025-30364 Information
Mar 28, 2025
cve
Description
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL commands which can compromise the confidentiality integrity and availability of stored data. Version 3.2.8 fixes the issue.
Reference
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-x3ff-5qp7-43qv https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-x3ff-5qp7-43qv
Share on: