CVE-2025-53527

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:3.3.3:*:*:*:*:*:*:*

History

10 Jul 2025, 21:16

Type Values Removed Values Added
CPE cpe:2.3:a:wegia:wegia:3.3.3:*:*:*:*:*:*:*
First Time Wegia
Wegia wegia
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff - Exploit, Vendor Advisory
References () https://github.com/LabRedesCefetRJ/WeGIA/commit/9de9a741d1d26ae76b2215a32660817d9bd452aa - () https://github.com/LabRedesCefetRJ/WeGIA/commit/9de9a741d1d26ae76b2215a32660817d9bd452aa - Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

08 Jul 2025, 14:15

Type Values Removed Values Added
CWE CWE-89

07 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 17:15

Updated : 2025-07-10 21:16


NVD link : CVE-2025-53527

Mitre link : CVE-2025-53527


JSON object : View

Products Affected

wegia

  • wegia
CWE

No CWE.