CVE-2025-22141

HIGH

WeGIA < 3.2.8 - SQL Injection via cargo Parameter in verificar_recursos_cargo.php Endpoint

Title source: llm
STIX 2.1

Description

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0036
EPSS Percentile 58.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
wegia/wegia < 3.2.8
Published Jan 08, 2025
Tracked Since Feb 18, 2026