CVE 9.4 CRITICAL

WeGIA SQL Injection via ‘id_dependente’ param at endpoint `/html/funcionario/dependente_documento.php`_CVE-2025-62360

9.4 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Description

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

AI Analysis

AI processing failed - returned non-JSON response

Basic Information

ID CVE-2025-62360
Source GitHub_M
Published Oct 13, 2025 at 21:24

Affected Product

Vendor LabRedesCefetRJ
Product WeGIA
Version < 3.5.1
Affected Versions LabRedesCefetRJ WeGIA < 3.5.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.