Beveiligingsadvies

CVE-2025-53527

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-07-07 16:47:04
Laatst bijgewerkt 2025-07-08 13:39:36
Toegewezen door GitHub_M
CVSS-score 8.3
Status PUBLISHED

Beschrijving

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.