CVE 8.8 HIGH

WeGIA has SQL Injection via Session Variable Override in DespachoControle.php_CVE-2026-40285

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the attacker-controlled value is then interpolated directly into a raw SQL query, allowing any authenticated user to query the database under an arbitrary identity. Version 3.6.10 fixes the issue.

AI Analysis

SQL injection vulnerability in WeGIA via session variable override

Basic Information

ID CVE-2026-40285
Source GitHub_M
Published Apr 17, 2026 at 20:25

Affected Product

Vendor LabRedesCefetRJ
Product WeGIA
Version < 3.6.10
Affected Versions LabRedesCefetRJ WeGIA < 3.6.10

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor LabRedesCefetRJ
Product WeGIA
Version < 3.6.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.