CVE-2025-46828: Unauthenticated SQL Injection on get_socios.php endpoint
WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint /html/socio/sistema/getsocios.php, specifically in the query parameter. This issue allows attackers to inject and execute arbitrary SQL statements against the application's underlying database. As a result, it may lead to data exfiltration, authentication bypass, or complete database compromise. Version 3.3.1 fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46828?
CVE-2025-46828 has a critical severity level due to its ability to allow unauthenticated SQL injection attacks.
How do I fix CVE-2025-46828?
To fix CVE-2025-46828, update WeGIA to version 3.3.1 or later, which addresses this vulnerability.
What are the consequences of exploiting CVE-2025-46828?
Exploitation of CVE-2025-46828 may allow attackers to extract sensitive data from the database and manipulate the system.
Which software versions are affected by CVE-2025-46828?
CVE-2025-46828 affects all versions of WeGIA up to and including version 3.3.0.
Is authentication required to exploit CVE-2025-46828?
No, CVE-2025-46828 can be exploited without authentication.