CVE-2025-26608

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 18, 2025
Updated: Feb 28, 2025
CWE ID 284
CWE ID 89

Summary

CVE-2025-26608 is a SQL Injection vulnerability affecting the WeGIA open-source Web Manager for Portuguese language users. The `dependente_docdependente.php` endpoint in the application was identified as the source of the issue. This vulnerability enables attackers to execute arbitrary SQL queries, potentially granting unauthorized access to sensitive data. All users are urged to upgrade to version 3.2.13, which addresses this vulnerability. No known workarounds are available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share