SQL injection in WeGIA - CVE-2025-46828

 

SQL injection in WeGIA - CVE-2025-46828

Published: April 30, 2026


Vulnerability identifier: #VU128703
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-46828
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL statements against the database.

The vulnerability exists due to SQL injection in the /html/socio/sistema/get_socios.php endpoint when processing the POST query parameter. A remote attacker can send a specially crafted POST request to execute arbitrary SQL statements against the database.

This may lead to data exfiltration, authentication bypass, or complete database compromise.


Affected software

WeGIA

How to mitigate CVE-2025-46828

Install security update from vendor's website.

WeGIA - update to 3.3.1

External References

Related Security Bulletins