Cyber Posture

CVE-2025-24906

CriticalPublic PoC

Published: 03 February 2025

Published
03 February 2025
Modified
13 February 2025
KEV Added
Patch
CVSS Score 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0038 59.4th percentile
Risk Priority 20 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.

Security Summary

CVE-2025-24906 is a SQL injection vulnerability (CWE-89) discovered in the WeGIA application, a web manager for charitable institutions. The flaw affects the `get_detalhes_cobranca.php` endpoint and has a CVSS v3.1 base score of 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). It impacts WeGIA versions prior to 3.2.12.

An authorized attacker can exploit this vulnerability remotely over the network to execute arbitrary SQL queries, enabling access to or deletion of sensitive information. The CVSS metrics indicate low attack complexity, no required privileges or user interaction, and high impacts on confidentiality, integrity, and availability.

The vulnerability has been addressed in WeGIA version 3.2.12, with all users advised to upgrade immediately. No workarounds are known. Additional details are available in the GitHub Security Advisory at https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jpph-g9p7-9jrm.

Details

CWE(s)
CWE-89

Affected Products

wegia
wegia
≤ 3.2.12

MITRE ATT&CK Enterprise Techniques

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

SQL injection in public-facing web app enables remote unauthenticated exploitation for data access/deletion, directly mapping to T1190 Exploit Public-Facing Application.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References