CVE-2026-33133

Source
https://cve.org/CVERecord?id=CVE-2026-33133
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33133.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-33133
Aliases
  • GHSA-qqff-p8fc-hg5f
Published
2026-03-20T10:31:38.420Z
Modified
2026-08-07T11:50:55.986698754Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
WeGIA has an arbitrary SQL execution vulnerability via crafted backup archive
Details

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator accounts, modify existing passwords, or execute any database operation. This was introduced in commit 370104c. This issue was patched in version 3.6.7.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/33xxx/CVE-2026-33133.json",
    "cwe_ids": [
        "CWE-89"
    ]
}
References

Affected packages

Git / github.com/labredescefetrj/wegia

Affected ranges

Type
GIT
Repo
https://github.com/labredescefetrj/wegia
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "3.6.5"
        },
        {
            "fixed": "3.6.7"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

3.*
3.6.5
3.6.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-33133.json"