Vulnerabilities
Vulnerable Software
Wegia:  >> Wegia  >> 3.2.14  Security Vulnerabilities
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.
CVSS Score
9.8
EPSS Score
0.119
Published
2025-02-24
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was discovered in the WeGIA application prior to version 3.2.15 at the `adicionar_tipo_exame.php` endpoint. This vulnerability allows an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.2.15 contains a patch for the issue.
CVSS Score
8.8
EPSS Score
0.005
Published
2025-02-24


Contact Us

Shodan ® - All rights reserved