216.73.217.22

CVE-2025-30364

· Published 27/03/2025 17:15 · Modified 28/03/2025 18:11

Labels: CVE-2025-30364 2025-03-27CVE-2025-30364CWE-89[email protected]

Essential information

Published
27/03/2025 17:15
Modified
28/03/2025 18:11
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL commands, which can compromise the confidentiality, integrity, and availability of stored data. Version 3.2.8 fixes the issue.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wegia / wegia cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

References