CVE-2025-22140: WeGIA SQL Injection (Blind Time-Based) endpoint 'dependente_listar_um.php' parameter 'id_dependente'
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependentelistarum.php endpoint, specifically in the iddependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22140?
CVE-2025-22140 is characterized as a critical severity vulnerability due to the potential for remote code execution via SQL injection.
How do I fix CVE-2025-22140?
To fix CVE-2025-22140, ensure you validate and sanitize all inputs on the /html/funcionario/dependente_listar_um.php endpoint.
Which version of WeGIA is affected by CVE-2025-22140?
CVE-2025-22140 affects WeGIA versions up to and including 3.2.8.
What type of vulnerability is CVE-2025-22140?
CVE-2025-22140 is a SQL Injection vulnerability that allows attackers to execute arbitrary SQL commands.
What is the impact of exploiting CVE-2025-22140?
Exploiting CVE-2025-22140 can lead to unauthorized access to the database and potentially compromise sensitive data.