SQL injection in WeGIA - CVE-2025-30367
Published: March 27, 2025 / Updated: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information, modify database records, or cause a denial of service.
The vulnerability exists due to SQL injection in the nextPage parameter of the /WeGIA/controle/control.php endpoint when handling requests. A remote user can send a specially crafted request to disclose sensitive information, modify database records, or cause a denial of service.