Back

CRITICAL

SQL Injection endpoint 'salvar_cargo.php' parameter 'id_cargo' in WeGIA

Published Feb 3, 2025

Description

WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `salvar_cargo.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 3, 2025
Updated Aug 22, 2025
Reserved Jan 27, 2025
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner GitHub_M
Published Feb 3, 2025
Updated Aug 22, 2025
Exploited since n/a
EUVD-2025-3983