CVE-2025-24905: SQL Injection endpoint 'get_codigobarras_cobranca.php' parameter 'codigo' in WeGIA
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, getcodigobarrascobranca.php endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24905?
CVE-2025-24905 is classified as a critical SQL Injection vulnerability that allows attackers to execute arbitrary SQL queries.
How do I fix CVE-2025-24905?
To fix CVE-2025-24905, update the WeGIA application to version 3.2.12 or later, which addresses this vulnerability.
What type of attack does CVE-2025-24905 allow?
CVE-2025-24905 allows an authorized attacker to execute arbitrary SQL queries, resulting in potential access to or deletion of sensitive data.
Which version of WeGIA is affected by CVE-2025-24905?
CVE-2025-24905 affects WeGIA versions prior to 3.2.12.
Where can I find more information about CVE-2025-24905?
More information about CVE-2025-24905 can be found in security advisories from trusted security sources and vulnerability databases.