CVE-2025-26607

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 28, 2025
CWE ID 284
CWE ID 89

Summary

CVE-2025-26607 is a SQL Injection vulnerability affecting the WeGIA open-source Web Manager for Portuguese language users. The `documento_excluir.php` endpoint in the application was identified as the source of the issue. This vulnerability enables attackers to execute arbitrary SQL queries, potentially granting unauthorized access to sensitive information. The latest version, 3.2.13, addresses this vulnerability, and all users are recommended to upgrade without delay. No known workarounds exist for this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share