CVE-2025-30364: WeGIA vulnerable to SQL Injection (Blind Time-Based) in remuneracao.php parameter id_funcionario
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the idfuncionario parameter. This vulnerability allows the execution of arbitrary SQL commands, which can compromise the confidentiality, integrity, and availability of stored data. Version 3.2.8 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30364?
The severity of CVE-2025-30364 is high due to the potential for SQL injection allowing arbitrary command execution.
How do I fix CVE-2025-30364?
To fix CVE-2025-30364, upgrade to WeGIA version 3.2.8 or later.
Where is the CVE-2025-30364 vulnerability located?
CVE-2025-30364 vulnerability is located in the /WeGIA/html/funcionario/remuneracao.php endpoint in the id_funcionario parameter.
What kind of attack can be performed using CVE-2025-30364?
CVE-2025-30364 can be exploited to execute arbitrary SQL commands on the database.
Which versions of WeGIA are affected by CVE-2025-30364?
Versions of WeGIA prior to 3.2.8 are affected by CVE-2025-30364.