CVE-2025-26607
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Feb 18, 2025
Updated: Feb 28, 2025
CWE ID 284
CWE ID 89
Summary
CVE-2025-26607 is a SQL Injection vulnerability affecting the WeGIA open-source Web Manager for Portuguese language users. The `documento_excluir.php` endpoint in the application was identified as the source of the issue. This vulnerability enables attackers to execute arbitrary SQL queries, potentially granting unauthorized access to sensitive information. The latest version, 3.2.13, addresses this vulnerability, and all users are recommended to upgrade without delay. No known workarounds exist for this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- WeGIA
Affected Vendors
- WE Giá