CVE-2025-24902: SQL Injection endpoint 'salvar_cargo.php' parameter 'id_cargo' in WeGIA
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, salvarcargo.php endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24902?
The severity of CVE-2025-24902 is critical due to the potential for unauthorized access and data manipulation.
How do I fix CVE-2025-24902?
To fix CVE-2025-24902, update the WeGIA application to the latest version above 3.2.12 and validate user inputs to prevent SQL injection.
What systems are affected by CVE-2025-24902?
CVE-2025-24902 affects the WeGIA Web Manager for Charitable Institutions versions up to 3.2.12.
What are the potential impacts of CVE-2025-24902?
Exploitation of CVE-2025-24902 can lead to unauthorized SQL query execution, data theft, or data loss.
Who can exploit CVE-2025-24902?
CVE-2025-24902 can be exploited by authorized attackers who have access to the WeGIA application.