CVE-2025-53091
27.06.2025, 15:15
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in version 3.3.3 the almox parameter of the `/controle/getProdutosPorAlmox.php` endpoint. This issue allows any unauthenticated attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. Version 3.4.0 fixes the issue.
Vendor | Product | Version |
---|---|---|
wegia | wegia | 𝑥 < 3.4.0 |
𝑥
= Vulnerable software versions