SQL Injection Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2026-33133

8.6HIGH

Key Information:

Status
Vendor
CVE Published:
20 March 2026

What is CVE-2026-33133?

WeGIA, a web management tool designed for charitable organizations, has a critical vulnerability in its loadBackupDB() function. This flaw allows attackers to upload malicious SQL files that the application imports without proper content validation. As a result, attackers can execute arbitrary SQL commands, leading to the creation of rogue administrator accounts, modification of user credentials, or unauthorized database access. Users are urged to update to version 3.6.7, where this security issue has been addressed.

Affected Version(s)

WeGIA >= 3.6.5, < 3.6.7

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.