WeGIA SQL Injection Vulnerability in nextPage Parameter of control.php

Vulnerability

A SQL injection vulnerability exists in WeGIA version 3.2.0, specifically within the nextPage parameter of the controle/control.php endpoint. This vulnerability allows attackers to manipulate SQL queries, potentially leading to unauthorized access to sensitive database information, including table names and personal data. Exploitation of this vulnerability could also allow for the manipulation or deletion of database records, and in some cases, could disrupt system availability.

Impact

Exploitation of this vulnerability could result in unauthorized access to and manipulation of database information, including sensitive personal data. Additionally, it could disrupt the application's normal functioning by causing system downtime.

Reproduction

The vulnerability can be reproduced by sending a crafted request to the controle/control.php endpoint with a payload that exploits the SQL injection flaw in the nextPage parameter. This can be done manually or using automated tools like SQLMap, which can exploit the vulnerability and dump the database contents.

Remediation

Users are advised to update to WeGIA version 3.2.0 or later, where this vulnerability has been addressed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.