SQL injection in WeGIA - CVE-2025-53946
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to SQL injection in the /html/saude/profile_paciente.php endpoint when processing the id_fichamedica parameter. A remote user can send a specially crafted request to disclose sensitive information.
The issue can be used to enumerate database schemas, tables, users, and versions.