SQL injection in WeGIA - CVE-2025-53823
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in the processa_deletar_socio.php endpoint parameter id_socio when handling crafted POST requests. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
The issue is described as a blind time-based SQL injection.