WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Jul 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1. | |
Title | WeGIA allows Time-Based Blind SQL Injection in the relatorio_geracao.php endpoint | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-07T16:47:04.624Z
Updated: 2025-07-07T16:47:04.624Z
Reserved: 2025-07-02T15:15:11.514Z
Link: CVE-2025-53527

No data.

Status : Received
Published: 2025-07-07T17:15:29.860
Modified: 2025-07-07T17:15:29.860
Link: CVE-2025-53527

No data.