SQL Injection Vulnerability in WeGIA Web Manager by LabRedes
CVE-2025-54058
9.4CRITICAL
What is CVE-2025-54058?
An SQL Injection vulnerability has been discovered in the WeGIA web manager, specifically in the idatendido_familiares
parameter of the /html/funcionario/dependente_editarEndereco.php
endpoint. This flaw, present in versions prior to 3.4.6, enables attackers to manipulate SQL queries that can expose sensitive data from the database, including names of tables and confidential user information. It is strongly advised that users upgrade to version 3.4.6 to mitigate this security risk.
Affected Version(s)
WeGIA < 3.4.6