Metrics
Affected Vendors & Products
Sun, 13 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Fri, 11 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Mon, 07 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 07 Jul 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properly sanitized or validated before being used in a SQL query, allowing an unauthenticated attacker to inject arbitrary SQL commands. The vulnerability is fixed in 3.4.3. | |
Title | WeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter) | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-07T18:02:36.711Z
Reserved: 2025-07-02T15:15:11.514Z
Link: CVE-2025-53529

Updated: 2025-07-07T18:02:18.164Z

Status : Analyzed
Published: 2025-07-07T17:15:30.030
Modified: 2025-07-10T21:16:36.407
Link: CVE-2025-53529

No data.