CVE-2025-23220
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jan 20, 2025
Updated: Jan 21, 2025
CWE ID 89
Summary
CVE-2025-23220 is a SQL Injection vulnerability affecting the WeGIA web manager, a Portuguese language application primarily used by charitable institutions. The flaw was discovered in the adicionar_raca.php endpoint, which enabled attackers to execute arbitrary SQL commands in the database. This vulnerability could lead to unauthorized access to sensitive information, including a complete dump of the application's database, underlining its severity. The issue has been resolved in version 3.2.10.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.