Description
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was identified in the Atendido_ocorrenciaControle endpoint via the id_memorando parameter. This flaw allows for full database exfiltration, exposure of sensitive PII, and potential arbitrary file reads in misconfigured environments. This vulnerability is fixed in 3.6.2.
Problem types
CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Product status
References
github.com/.../WeGIA/security/advisories/GHSA-xfmp-2hf9-gfjp
github.com/LabRedesCefetRJ/WeGIA/pull/1333
github.com/LabRedesCefetRJ/WeGIA/releases/tag/3.6.2