SQL Injection Vulnerability in WeGIA Web Manager for Portuguese Users
CVE-2025-67501
What is CVE-2025-67501?
The WeGIA open-source web management tool for institutions exhibits an SQL Injection vulnerability in its /html/matPat/editar_categoria.php endpoint. This security flaw arises from insufficient validation and sanitization of user inputs, specifically in the id_categoria parameter. As a result, attackers can inject harmful SQL commands that the application may execute directly, potentially leading to unauthorized data exposure or manipulation. Users are advised to upgrade to version 3.5.5, where the issue has been addressed to enhance security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.5.5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
