CVE-2025-61603 is a critical SQL Injection vulnerability affecting WeGIA, a web manager for charitable institutions, specifically in versions 3.4.12 and below. The flaw exists in the /controle/control.php endpoint via the 'descricao' parameter, allowing unauthenticated attackers to execute arbitrary SQL commands. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 95/100, this vulnerability poses a significant risk of compromising data confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community discussion with 11 mentions, indicating awareness among security researchers. Organizations using WeGIA are urged to upgrade to version 3.5.0 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.0CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.