SQL injection in WeGIA - CVE-2025-58454
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the listar_despachos.php endpoint when handling the id_memorando parameter in GET requests. A remote user can send a specially crafted parameter value to disclose sensitive information.
Exploitation may also enable arbitrary SQL query execution and time-delay queries.