CVE-2025-53527
07.07.2025, 17:15
WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.
| Vendor | Product | Version |
|---|---|---|
| wegia | wegia | 3.3.3 |
𝑥
= Vulnerable software versions