CVE-2025-61605 is a critical SQL Injection vulnerability affecting WeGIA web manager versions 3.4.12 and below, specifically in the /pet/profile_pet.php endpoint via the id_pet parameter. This allows unauthenticated attackers to execute arbitrary SQL commands, leading to complete compromise of database confidentiality, integrity, and availability. With a CVSS score of 9.8 (CRITICAL), it presents a significant risk, particularly for charitable organizations using the affected software. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion, and patching to version 3.5.0 or higher is strongly recommended.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.5.0CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.