CVE-2025-24906: SQL Injection endpoint 'get_detalhes_cobranca.php' parameter 'codigo' in WeGIA
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, getdetalhescobranca.php endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24906?
CVE-2025-24906 is considered a high severity SQL Injection vulnerability that can lead to unauthorized access or deletion of sensitive data.
How do I fix CVE-2025-24906?
To fix CVE-2025-24906, update WeGIA to version 3.2.12 or later, which addresses the SQL Injection vulnerability.
What kind of attack can be executed through CVE-2025-24906?
CVE-2025-24906 allows an authorized attacker to execute arbitrary SQL queries against the WeGIA application.
What are the risks of CVE-2025-24906 in WeGIA?
The risks of CVE-2025-24906 include potential unauthorized access to sensitive information and the ability to manipulate or delete data.
Is CVE-2025-24906 present in earlier versions of WeGIA?
Yes, CVE-2025-24906 is present in all versions of WeGIA prior to 3.2.12.