CVE-2026-31895: WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.php
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurarproduto.php. The idproduto parameter from $GET is directly interpolated into SQL queries without parameterization or sanitization. This vulnerability is fixed in 3.6.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-31895?
CVE-2026-31895 is considered a high severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2026-31895?
To fix CVE-2026-31895, upgrade WeGIA to version 3.6.6 or later to mitigate the SQL injection vulnerability.
What impact does CVE-2026-31895 have on WeGIA?
CVE-2026-31895 allows attackers to execute arbitrary SQL queries, potentially compromising sensitive data and altering database contents.
Which versions of WeGIA are affected by CVE-2026-31895?
CVE-2026-31895 affects all versions of WeGIA prior to version 3.6.6.
Is it necessary to take immediate action for CVE-2026-31895?
Yes, it is crucial to take immediate action to patch CVE-2026-31895 to prevent exploitation and potential data breaches.