← Back to browse · API

CVE-2025-30364

Severity
CRITICAL
CVSS
10.0
EPSS
0.00605
Risk score
40.21
CISA KEV
No
PoC
No
Published
2025-03-27
Modified
2025-03-27
First seen
2026-08-07
Aliases
EUVD-2025-8513
Products
LabRedesCefetRJ:WeGIA < 3.2.8
Sources
euvd EUVD-2025-8513

Description

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/html/funcionario/remuneracao.php, in the id_funcionario parameter. This vulnerability allows the execution of arbitrary SQL commands, which can compromise the confidentiality, integrity, and availability of stored data. Version 3.2.8 fixes the issue.

References