CVE-2025-24906
- EPSS 0.41%
- Veröffentlicht 03.02.2025 22:15:28
- Zuletzt bearbeitet 13.02.2025 18:59:59
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_cobranca.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, a...
CVE-2025-24020
- EPSS 0.32%
- Veröffentlicht 21.01.2025 18:15:18
- Zuletzt bearbeitet 13.02.2025 19:01:51
WeGIA is a Web manager for charitable institutions. An Open Redirect vulnerability was identified in the `control.php` endpoint of versions up to and including 3.2.10 of the WeGIA application. The vulnerability allows the `nextPage` parameter to be m...
CVE-2025-23218
- EPSS 0.48%
- Veröffentlicht 20.01.2025 16:15:28
- Zuletzt bearbeitet 28.02.2025 19:18:34
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_especie.php endpoint. This vulnerability all...
CVE-2025-23219
- EPSS 0.31%
- Veröffentlicht 20.01.2025 16:15:28
- Zuletzt bearbeitet 28.02.2025 19:18:34
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_cor.php endpoint. This vulnerability allows ...
CVE-2025-23220
- EPSS 0.31%
- Veröffentlicht 20.01.2025 16:15:28
- Zuletzt bearbeitet 28.02.2025 19:18:34
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_raca.php endpoint. This vulnerability allows...
CVE-2024-57035
- EPSS 0.2%
- Veröffentlicht 17.01.2025 21:15:10
- Zuletzt bearbeitet 18.03.2025 18:15:27
WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2024-57033
- EPSS 0.48%
- Veröffentlicht 17.01.2025 21:15:09
- Zuletzt bearbeitet 09.04.2025 18:30:54
WeGIA < 3.2.0 is vulnerable to Cross Site Scripting (XSS) via the dados_addInfo parameter of documentos_funcionario.php.
CVE-2024-57034
- EPSS 0.46%
- Veröffentlicht 17.01.2025 20:15:29
- Zuletzt bearbeitet 14.03.2025 18:15:30
WeGIA < 3.2.0 is vulnerable to SQL Injection in query_geracao_auto.php via the query parameter.
CVE-2024-57030
- EPSS 0.66%
- Veröffentlicht 17.01.2025 20:15:28
- Zuletzt bearbeitet 09.04.2025 18:24:20
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-57031
- EPSS 0.44%
- Veröffentlicht 17.01.2025 20:15:28
- Zuletzt bearbeitet 24.03.2025 18:15:21
WeGIA < 3.2.0 is vulnerable to SQL Injection in /funcionario/remuneracao.php via the id_funcionario parameter.