Aller au contenu

Fiche vulnérabilité

CVE-2025-53946 : faille élevée wegia wegia (CVSS 8.8)

Description

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.5 in the `id_funcionario` parameter of the `/html/saude/profile_paciente.php` endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive database information, such as table names and sensitive data. Version 3.4.5 fixes the issue.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • wegia wegia

Références

Rechercher une autre vulnérabilité dans la base CVE