CVE-2025-58454 - CVE House
Back to Database
Status published High CVE-2025-58454

WeGIA vulnerable to Blind Time-Based SQL Injection in endpoint 'listar_despachos.php' parameter 'id_memorando'

Vulnerability Description

WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/listar_despachos.php, in the id_memorando parameter. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.4.11 contains a patch.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-58454

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

LabRedesCefetRJ

View all reports →

Affected Software

WeGIA
Vulnerable Versions:
< 3.4.11

Timeline

Official Publish: September 8th, 2025
Last Modified: September 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)