SQL Injection Vulnerability in WeGIA Web Manager for Charitable Institutions by LabRedesCefetRJ
CVE-2026-40285
8.8HIGH
What is CVE-2026-40285?
WeGIA, a web manager for charitable institutions, harbors a SQL injection vulnerability in the UsuarioDAO.php file. Specifically, the cpf_usuario POST parameter can overwrite the session-stored user identity through insecure handling of user input in the DespachoControle::verificarDespacho() method. This flaw permits any authenticated user to execute arbitrary SQL queries, thereby accessing and potentially altering sensitive database information. The vulnerability has been addressed in version 3.6.10.
Affected Version(s)
WeGIA < 3.6.10
