SQL Injection Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2025-30364
What is CVE-2025-30364?
A SQL Injection vulnerability has been discovered in the WeGIA Web Manager, affecting all versions prior to 3.2.8. The flaw exists in the endpoint /WeGIA/html/funcionario/remuneracao.php, specifically in the id_funcionario parameter. This vulnerability could allow attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of sensitive data stored within the application. The issue has been addressed in version 3.2.8, and it is strongly recommended that users upgrade to this version or later to mitigate the risks associated with this security flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.2.8
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
