SQL Injection Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2026-33133
8.6HIGH
What is CVE-2026-33133?
WeGIA, a web management tool designed for charitable organizations, has a critical vulnerability in its loadBackupDB() function. This flaw allows attackers to upload malicious SQL files that the application imports without proper content validation. As a result, attackers can execute arbitrary SQL commands, leading to the creation of rogue administrator accounts, modification of user credentials, or unauthorized database access. Users are urged to update to version 3.6.7, where this security issue has been addressed.
Affected Version(s)
WeGIA >= 3.6.5, < 3.6.7
