Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-23220

Опубликовано: 20 янв. 2025
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_raca.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sensitive information. During the exploit, it was possible to perform a complete dump of the application's database, highlighting the severity of the flaw. This vulnerability is fixed in 3.2.10.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
Версия до 3.2.10 (исключая)

EPSS

Процентиль: 68%
0.00583
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89

EPSS

Процентиль: 68%
0.00583
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-89