WeGIA SQL Injection Vulnerability in adicionar_tipo_exame.php Endpoint

Vulnerability

A SQL Injection vulnerability exists in the WeGIA application for charitable institutions, in versions prior to 3.2.15. The issue is located in the 'adicionar_tipo_exame.php' endpoint, where authorized attackers can execute arbitrary SQL queries, potentially accessing sensitive information. The vulnerability arises from inadequate input validation, allowing exploitation through crafted SQL payloads.

Impact

Exploitation of this vulnerability allows attackers to execute arbitrary SQL queries, which could lead to unauthorized access to sensitive information, disruption of database services, or in some cases, uploading of arbitrary files.

Reproduction

To reproduce this vulnerability, send a POST request to the 'dao/pet/adicionar_tipo_exame.php' endpoint with a crafted 'tipo_exame' parameter that includes SQL injection payloads. The absence of input validation in the application allows the injected SQL to be executed, manipulating the database or extracting information.

Remediation

Users can upgrade to WeGIA version 3.2.15 or later, where this vulnerability has been patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.6
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.