SQL Injection Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2026-35395
8.8HIGH
What is CVE-2026-35395?
The WeGIA web manager, designed for charitable institutions, is susceptible to SQL injection due to improper validation of user inputs. An attacker can manipulate the id_memorando parameter, extracted directly from user requests, which is then interpolated into SQL queries without adequate sanitization. This flaw permits authenticated users to execute arbitrary commands on the database, posing a significant security risk. The vulnerability has been addressed in version 3.6.9.
Affected Version(s)
WeGIA < 3.6.9
