WeGIA SQL Injection Vulnerability in processa_deletar_socio.php Endpoint

Vulnerability

A SQL injection vulnerability has been identified in WeGIA versions prior to 3.4.5. The issue resides in the 'id_socio' parameter of the '/WeGIA/html/socio/sistema/processa_deletar_socio.php' endpoint. This vulnerability allows attackers to execute arbitrary SQL commands, potentially compromising the confidentiality, integrity, and availability of the application's data.

Impact

Exploitation of this vulnerability allows for arbitrary SQL command execution, leading to confidential data exfiltration, database compromise, and potential denial-of-service conditions through time-delay queries.

Reproduction

To reproduce this vulnerability, send a POST request to the '/WeGIA/html/socio/sistema/processa_deletar_socio.php' endpoint. Include the 'id_socio' parameter with a value of '1' and the 'pessoa' parameter with a value of 'fisica'. The request should be made with the appropriate headers to simulate a normal user interaction, such as 'User-Agent' and 'X-Requested-With'.

Remediation

Users can upgrade to WeGIA version 3.4.5 or later to address this vulnerability.

Added: Jul 14, 2025, 11:21 PM
Updated: Jul 14, 2025, 11:21 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
7.7
relevance
0.2
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.