CVE-2026-23723 is an authenticated SQL Injection vulnerability affecting WeGIA, a web manager for charitable institutions, in versions prior to 3.6.2. The flaw exists in the Atendido_ocorrenciaControle endpoint via the id_memorando parameter. This vulnerability carries a CVSS score of 7.2 (HIGH), indicating that an authenticated attacker can achieve full database exfiltration, expose sensitive PII, and potentially perform arbitrary file reads in misconfigured environments. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion, with 10 mentions, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.2CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.