SQL Injection Vulnerability in WeGIA Web Manager by LabRedes
CVE-2025-54058

9.4CRITICAL

Key Information:

Status
Vendor
CVE Published:
17 July 2025

What is CVE-2025-54058?

An SQL Injection vulnerability has been discovered in the WeGIA web manager, specifically in the idatendido_familiares parameter of the /html/funcionario/dependente_editarEndereco.php endpoint. This flaw, present in versions prior to 3.4.6, enables attackers to manipulate SQL queries that can expose sensitive data from the database, including names of tables and confidential user information. It is strongly advised that users upgrade to version 3.4.6 to mitigate this security risk.

Affected Version(s)

WeGIA < 3.4.6

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54058 : SQL Injection Vulnerability in WeGIA Web Manager by LabRedes