WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profilefuncionario.php endpoint. The idfuncionario parameter is not properly sanitized or validated before being used in a SQL query, allowing an unauthenticated attacker to inject arbitrary SQL commands. The vulnerability is fixed in 3.4.3.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/53xxx/CVE-2025-53529.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-89"
],
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "3.4.3"
}
],
"source": "AFFECTED_FIELD"
}
]
}