CVE-2025-24958: SQL Injection endpoint 'salvar_tag.php' parameter 'id_tag' in WeGIA
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, salvartag.php endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24958?
CVE-2025-24958 is classified as a critical vulnerability due to its potential to allow unauthorized SQL queries execution.
How do I fix CVE-2025-24958?
To fix CVE-2025-24958, it is recommended to update the WeGIA application to version 3.2.13 or later, which contains security patches.
Who is affected by CVE-2025-24958?
CVE-2025-24958 affects users of WeGIA Web Manager for Charitable Institutions versions prior to 3.2.13.
What type of vulnerability is CVE-2025-24958?
CVE-2025-24958 is a SQL Injection vulnerability affecting the `salvar_tag.php` endpoint.
What could an attacker achieve through CVE-2025-24958?
An attacker exploiting CVE-2025-24958 could execute arbitrary SQL queries, leading to unauthorized access or deletion of sensitive data.