CVE-2025-53823: WeGIA vulnerable to SQL Injection (Blind Time-Based) in `processa_deletar_socio.php` parameter `id_socio`
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerability in the endpoint /WeGIA/html/socio/sistema/processadeletarsocio.php, in the idsocio parameter. This vulnerability allows the execution of arbitrary SQL commands, which can compromise the confidentiality, integrity, and availability of stored data. Version 3.4.5 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53823?
CVE-2025-53823 has been classified as a high severity SQL Injection vulnerability.
How do I fix CVE-2025-53823?
To fix CVE-2025-53823, upgrade WeGIA to version 3.4.5 or later.
What is the impact of CVE-2025-53823?
The impact of CVE-2025-53823 includes unauthorized access and potential manipulation of the database.
Which versions of WeGIA are affected by CVE-2025-53823?
WeGIA versions prior to 3.4.5 are affected by CVE-2025-53823.
Where does CVE-2025-53823 occur in the application?
CVE-2025-53823 occurs in the endpoint `/WeGIA/html/socio/sistema/processa_deletar_socio.php` in the `id_socio` parameter.