CVE-2025-53527

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:3.3.3:*:*:*:*:*:*:*

History

10 Jul 2025, 21:16

Type Values Removed Values Added
CPE cpe:2.3:a:wegia:wegia:3.3.3:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://github.com/LabRedesCefetRJ/WeGIA/commit/9de9a741d1d26ae76b2215a32660817d9bd452aa - () https://github.com/LabRedesCefetRJ/WeGIA/commit/9de9a741d1d26ae76b2215a32660817d9bd452aa - Patch
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff - Exploit, Vendor Advisory
First Time Wegia
Wegia wegia

08 Jul 2025, 14:15

Type Values Removed Values Added
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-43xw-c4g6-jgff -
Summary
  • (es) WeGIA es un gestor web para instituciones benéficas. Se descubrió una vulnerabilidad de inyección SQL ciega basada en tiempo en el parámetro almox del endpoint /controle/relatorio_geracao.php. Este problema permite a un atacante inyectar consultas SQL arbitrarias, lo que podría provocar acceso no autorizado a los datos o una mayor explotación, dependiendo de la configuración de la base de datos. Esta vulnerabilidad se corrigió en la versión 3.4.1.

07 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 17:15

Updated : 2025-07-10 21:16


NVD link : CVE-2025-53527

Mitre link : CVE-2025-53527

CVE.ORG link : CVE-2025-53527


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')