CVE-2025-61603
WeGIA: SQL Injection (Blind Time-Based) Vulnerability in API `descricao` Parameter
Vexday Risk Score
28Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 9.4EPSS 0.4%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
02 oct 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue is fixed in version 3.5.0.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Productos afectados
LabRedesCefetRJ · WeGIA¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →