---
id: CVE-2025-61603
title: WeGIA is a Web manager for charitable institutions
summary: >-
  WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below
  include an SQL Injection vulnerability which was identified in the
  /controle/control.php endpoint, specifically in the descricao parameter. This
  vulnerability …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: wegia
product: wegia
affected:
  - wegia < 3.5.0
patched:
  - wegia 3.5.0
published: '2025-10-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T23:10:00.213'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61603'
references:
  - url: >-
      https://github.com/LabRedesCefetRJ/WeGIA/commit/84958eed73741a544859eea297908db3b83b3833
    label: security-advisories@github.com
  - url: >-
      https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-v8hm-pq8g-c7j4
    label: security-advisories@github.com
  - url: >-
      https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-v8hm-pq8g-c7j4
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00425
epssPercentile: 0.34779
ingestedAt: '2026-10-08T23:16:47.359Z'
---

## Overview

WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue is fixed in version 3.5.0.

## Affected

- `wegia < 3.5.0`

## Remediation

Upgrade past the affected range:

- `wegia 3.5.0`
