CVE-2026-31895 HIGH

CVE-2026-31895: WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.php

Vendor Labredescefetrj
Product WeGIA
Weakness CWE-89 · SQLi
Published March 11, 2026
Last update March 11, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

Description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is directly interpolated into SQL queries without parameterization or sanitization. This vulnerability is fixed in 3.6.6.

Key dates

Disclosure timeline

March 11, 2026 CVE published
March 11, 2026 Record updated