216.73.216.233

CVE-2026-40285

· Published 17/04/2026 21:16 · Modified 17/04/2026 21:16

Labels: CVE-2026-40285 2026-04-17CVE-2026-40285CWE-89[email protected]

Essential information

Published
17/04/2026 21:16
Modified
17/04/2026 21:16
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the attacker-controlled value is then interpolated directly into a raw SQL query, allowing any authenticated user to query the database under an arbitrary identity. Version 3.6.10 fixes the issue.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wegia / wegia cpe:2.3:a:wegia:wegia:<3.6.10:*:*:*:*:*:*:*

References