SQL injection in WeGIA - CVE-2025-30364
Published: March 27, 2025 / Updated: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary SQL commands.
The vulnerability exists due to SQL injection in the remuneracao.php endpoint when processing the id_funcionario parameter. A remote attacker can send a specially crafted request to execute arbitrary SQL commands.
The issue is blind time-based and may be used to exfiltrate confidential data or cause a denial of service through time-delay queries.