SQL Injection Vulnerability in WeGIA Web Manager by LabRedes
CVE-2025-54058
9.4CRITICAL
What is CVE-2025-54058?
An SQL Injection vulnerability has been discovered in the WeGIA web manager, specifically in the idatendido_familiares parameter of the /html/funcionario/dependente_editarEndereco.php endpoint. This flaw, present in versions prior to 3.4.6, enables attackers to manipulate SQL queries that can expose sensitive data from the database, including names of tables and confidential user information. It is strongly advised that users upgrade to version 3.4.6 to mitigate this security risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.4.6
References
CVSS V4
Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
