


Perceptive Security
SOC/SIEM Consultancy

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_…
Published:
10 maart 2026 om 23:00:00
Alert date:
11 maart 2026 om 21:03:26
Source:
nvd.nist.gov
Web Technologies, Database & Storage
A critical SQL injection vulnerability exists in WeGIA web manager for charitable institutions prior to version 3.6.6. The vulnerability occurs in the remover_produto_ocultar.php script which uses extract($_REQUEST) to populate local variables and directly concatenates them into SQL queries executed via PDO::query. This allows authenticated or auth-bypassed attackers to execute arbitrary SQL commands, potentially leading to data exfiltration or denial of service through time-based delays. The vulnerability has been fixed in version 3.6.6.
Technical details
Mitigation steps:
Affected products:
WeGIA
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-31896
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-w7g3-87cr-8m83
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
