8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the attacker-controlled value is then interpolated directly into a raw SQL query, allowing any authenticated user to query the database under an arbitrary identity. Version 3.6.10 fixes the issue.
AI Analysis
SQL injection vulnerability in WeGIA via session variable override
Basic Information
ID
CVE-2026-40285
Source
GitHub_M
Published
Apr 17, 2026 at 20:25
Affected Product
Vendor
LabRedesCefetRJ
Product
WeGIA
Version
< 3.6.10
Affected Versions
LabRedesCefetRJ WeGIA < 3.6.10
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
LabRedesCefetRJ
Product
WeGIA
Version
< 3.6.10