PT-2026-24797 · Labredescefetrj+2 · Wegia

·

CVE-2026-31895

·

Published

2026-03-11

·

Updated

2026-03-11

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.6
Description WeGIA is a web manager for charitable institutions. Versions of the software prior to 3.6.6 contain a SQL injection issue in the ‘html/matPat/restaurar produto.php’ file. The id produto parameter, received via the GET request, is directly used in SQL queries without proper sanitization or parameterization. This allows for potential manipulation of database queries.
Recommendations Update to version 3.6.6 or later.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31895
GHSA-M39R-P62F-VMQM

Affected Products

Wegia