CVE-2025-26614: SQL Injection endpoint 'deletar_documento.php' parameter 'id_cargo' in WeGIA
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, deletardocumento.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. This issue has been addressed in version 3.2.14 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.14
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26614?
CVE-2025-26614 is considered a high severity vulnerability due to its potential for SQL Injection attacks.
How do I fix CVE-2025-26614?
To fix CVE-2025-26614, it is recommended to update WeGIA to version 3.2.14 or higher and sanitize all user inputs.
What is the impact of exploiting CVE-2025-26614?
Exploiting CVE-2025-26614 allows an authorized attacker to execute arbitrary SQL queries on the WeGIA application.
Who is affected by CVE-2025-26614?
CVE-2025-26614 affects users of WeGIA versions prior to 3.2.14.
Is CVE-2025-26614 being actively exploited?
While there is no current confirmation of active exploitation, it is crucial to address CVE-2025-26614 promptly to mitigate risk.