SQL injection in WeGIA - CVE-2025-62360
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper neutralization of special elements used in an SQL command in the /html/funcionario/dependente_documento.php endpoint when processing a POST request containing the id_dependente parameter. A remote attacker can send a specially crafted POST request to disclose sensitive information.
Successful exploitation requires that the supplied id_dependente value exists in the database.