SQL injection in WeGIA - CVE-2025-23220

 

SQL injection in WeGIA - CVE-2025-23220

Published: January 20, 2025 / Updated: May 2, 2026


Vulnerability identifier: #VU129032
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-23220
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary SQL commands and disclose sensitive information.

The vulnerability exists due to SQL injection in the adicionar_raca.php endpoint when handling a POST request containing the raca parameter. A remote attacker can send a specially crafted request to execute arbitrary SQL commands and disclose sensitive information.

The issue was demonstrated by dumping database contents, including data from the pessoa table.


Affected software

WeGIA

How to mitigate CVE-2025-23220

Install security update from vendor's website.

WeGIA - update to 3.2.10

External References

Related Security Bulletins