WeGIA
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*
- <= 3.4.4
A SQL injection vulnerability has been identified in WeGIA versions prior to 3.4.5. The issue resides in the 'id_socio' parameter of the '/WeGIA/html/socio/sistema/processa_deletar_socio.php' endpoint. This vulnerability allows attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of the application's data.
Exploitation of this vulnerability allows for arbitrary SQL command execution, leading to confidential data exfiltration, database compromise, and potential denial-of-service conditions through time-delay queries.
To reproduce this vulnerability, send a POST request to the '/WeGIA/html/socio/sistema/processa_deletar_socio.php' endpoint. Include the 'id_socio' parameter with a value of '1' and the 'pessoa' parameter with a value of 'fisica'. The request should be made with the appropriate headers to simulate a normal user interaction, such as 'User-Agent' and 'X-Requested-With'.
Users can upgrade to WeGIA version 3.4.5 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.