CVE-2025-24957: SQL Injection endpoint 'get_detalhes_socio.php' parameter 'id_socio' in WeGIA
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, getdetalhessocio.php endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24957?
The CVE-2025-24957 vulnerability is considered high severity due to the potential for unauthorized SQL execution.
How do I fix CVE-2025-24957?
To fix CVE-2025-24957, update the WeGIA application to version 3.2.12 or later, which addresses the SQL Injection issue.
What type of vulnerability is CVE-2025-24957?
CVE-2025-24957 is a SQL Injection vulnerability that can allow attackers to execute arbitrary SQL queries.
Who is affected by CVE-2025-24957?
Any user of the WeGIA Web Manager for Charitable Institutions version earlier than 3.2.12 is affected by CVE-2025-24957.
What can an attacker achieve with CVE-2025-24957?
An attacker can exploit CVE-2025-24957 to gain unauthorized access to or delete sensitive information from the database.