---
id: CVE-2025-62179
title: >-
  WeGIA is an open source Web Manager for Institutions with a focus on
  Portuguese language users
summary: >-
  WeGIA is an open source Web Manager for Institutions with a focus on
  Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was
  identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php
  endpoint, spe…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
vendor: wegia
product: wegia
affected:
  - wegia < 3.5.1
patched:
  - wegia 3.5.1
published: '2025-10-13'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62179'
references:
  - url: >-
      https://github.com/LabRedesCefetRJ/WeGIA/commit/885972c55c3a06b5275120e88bb1113754a63b26
    label: security-advisories@github.com
  - url: >-
      https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-x36x-x5j4-wfjf
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00427
epssPercentile: 0.34931
ingestedAt: '2026-10-08T12:39:48.708Z'
---

## Overview

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/cadastro_funcionario_pessoa_existente.php endpoint, specifically in the cpf parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.

## Affected

- `wegia < 3.5.1`

## Remediation

Upgrade past the affected range:

- `wegia 3.5.1`
