SQL injection in WeGIA - CVE-2026-23723
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the Atendido_ocorrenciaControle endpoint when handling the id_memorando parameter. A remote privileged user can send a specially crafted request to disclose sensitive information.
In misconfigured environments where the database FILE privilege is enabled, local file contents may also be exposed.