Security Advisory

CVE-2025-53527

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-07 16:47:04
Last updated 2025-07-08 13:39:36
Assigner GitHub_M
CVSS score not scored
State PUBLISHED

Description

WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configuration. This vulnerability is fixed in 3.4.1.