CVE-2025-62177
- EPSS 0.48%
- Veröffentlicht 13.10.2025 21:09:29
- Zuletzt bearbeitet 20.10.2025 16:06:57
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar.php endpoint, specifically in the id_funcionario p...
CVE-2025-61665
- EPSS 0.46%
- Veröffentlicht 02.10.2025 20:39:09
- Zuletzt bearbeitet 07.10.2025 15:41:23
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated atta...
CVE-2025-61606
- EPSS 0.2%
- Veröffentlicht 02.10.2025 20:25:58
- Zuletzt bearbeitet 07.10.2025 15:41:49
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=F...
CVE-2025-61605
- EPSS 0.39%
- Veröffentlicht 02.10.2025 20:13:02
- Zuletzt bearbeitet 07.10.2025 15:42:02
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified in the /pet/profile_pet.php endpoint, specifically in the id_pet parameter. This vulner...
CVE-2025-61604
- EPSS 0.16%
- Veröffentlicht 02.10.2025 20:09:23
- Zuletzt bearbeitet 07.10.2025 15:42:57
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Cross-Site Request Forgery (CSRF) vulnerability. The delete operation for the Almoxarifado entity is exposed via HTTP GET without CSRF pr...
CVE-2025-61603
- EPSS 0.39%
- Veröffentlicht 02.10.2025 19:53:36
- Zuletzt bearbeitet 07.10.2025 15:43:15
WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attack...
CVE-2025-59939
- EPSS 0.35%
- Veröffentlicht 27.09.2025 01:15:43
- Zuletzt bearbeitet 06.10.2025 15:05:36
WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the following parameters: nomeClasse=ProdutoControle&metodo=excluir&id_produto=[malicious comman...
CVE-2025-58745
- EPSS 0.71%
- Veröffentlicht 08.09.2025 22:40:56
- Zuletzt bearbeitet 17.09.2025 16:24:10
WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at endpoint `/html/socio/sistema/controller/controla_x...
CVE-2025-58454
- EPSS 0.34%
- Veröffentlicht 08.09.2025 22:35:04
- Zuletzt bearbeitet 17.09.2025 16:29:29
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/listar_despachos.php, in the id_memorando parameter. This vulnerability allow an ...
CVE-2025-58453
- EPSS 0.34%
- Veröffentlicht 08.09.2025 22:28:40
- Zuletzt bearbeitet 17.09.2025 16:31:24
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/exibe_anexo.php, in the id_anexo parameter. This vulnerability allow an authoriz...