CVE-2025-46828 CRITICAL

CVE-2025-46828: Unauthenticated SQL Injection on get_socios.php endpoint

Vendor Labredescefetrj
Product WeGIA
Weakness CWE-89 · SQLi
Published May 7, 2025
Last update May 7, 2025

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

WeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3.0 in the endpoint `/html/socio/sistema/get_socios.php`, specifically in the query parameter. This issue allows attackers to inject and execute arbitrary SQL statements against the application's underlying database. As a result, it may lead to data exfiltration, authentication bypass, or complete database compromise. Version 3.3.1 fixes the issue.

Key dates

02Disclosure timeline

May 7, 2025 CVE published
May 7, 2025 Record updated

Related vulnerabilities

04Related CVE