CVE-2025-23218

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Jan 20, 2025
Updated: Jan 21, 2025
CWE ID 89

Summary

CVE-2025-23218 is a SQL Injection vulnerability discovered in the WeGIA web manager, a Portuguese open-source application primarily used by charitable institutions. The affected endpoint is adicionar_especie.php. This weakness enables attackers to inject malicious SQL queries, gaining unauthorized access to sensitive data. The breach was demonstrated to result in a complete database dump, underscoring its severity. The vulnerability has been addressed in WeGIA version 3.2.10.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share