SQL Injection Vulnerability in WeGIA Web Manager by LabRedesCefetRJ
CVE-2025-54079
9.4CRITICAL
What is CVE-2025-54079?
A SQL Injection vulnerability has been detected in WeGIA, an open source web management tool designed for Portuguese charitable institutions. This flaw exists in the idatendido
parameter of the /html/atendido/Profile_Atendido.php
endpoint in versions prior to 3.4.6. An authenticated attacker can exploit this vulnerability to execute arbitrary SQL queries, thereby gaining access to sensitive information stored within the database. We recommend updating to version 3.4.6 or later, wherein this issue has been addressed.
Affected Version(s)
WeGIA < 3.4.6