CVE-2025-26610: SQL Injection endpoint 'restaurar_produto_desocultar.php' parameter 'id_produto' in WeGIA
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, restaurarprodutodesocultar.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. This issue has been addressed in version 3.2.13 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.13
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26610?
CVE-2025-26610 has a medium severity due to its potential for SQL injection exploitation by authorized attackers.
How do I fix CVE-2025-26610?
To fix CVE-2025-26610, update WeGIA to version 3.2.14 or later, which addresses the SQL injection vulnerability.
What versions of WeGIA are affected by CVE-2025-26610?
CVE-2025-26610 affects WeGIA versions prior to 3.2.13.
Can CVE-2025-26610 be exploited by unauthorized users?
No, CVE-2025-26610 requires an authorized user to exploit the SQL injection vulnerability.
What impacts does CVE-2025-26610 pose to my application?
CVE-2025-26610 can allow attackers to execute arbitrary SQL commands, potentially leading to data leakage or manipulation.