CVE-2025-27133: WeGIA has SQL Injection endpoint at 'dao/pet/adicionar_tipo_exame.php' parameter 'tipo_exame'
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the adicionartipoexame.php endpoint. This vulnerability allows an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.2.15 contains a patch for the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27133?
CVE-2025-27133 is classified as a critical SQL Injection vulnerability.
How do I fix CVE-2025-27133?
To fix CVE-2025-27133, upgrade the WeGIA application to version 3.2.15 or later.
What types of attacks can CVE-2025-27133 facilitate?
CVE-2025-27133 can facilitate unauthorized SQL queries that compromise the database.
What software versions are affected by CVE-2025-27133?
CVE-2025-27133 affects WeGIA versions prior to 3.2.15.
What endpoint is vulnerable in CVE-2025-27133?
The vulnerable endpoint in CVE-2025-27133 is `adicionar_tipo_exame.php`.