External risk intelligence

WeGIA SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-61605

WeGIA is a web-based management application designed for organizations. As a web application that manages records and profiles, it is commonly deployed as an internet-facing or intranet-facing web service accessible via standard browsers, making the application's endpoints directly reachable over the network in normal operational environments.

SQL Injection

Wegia

before 3.5.0

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

WeGIA, an open-source web manager used by charitable organizations, has a critical vulnerability that could allow attackers to execute malicious commands on its database. This issue, discovered in versions prior to 3.5.0, impacts the confidentiality, integrity, and availability of sensitive information.

  • Database commands can be run remotely.
  • Critical data could be compromised.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain access to WeGIA, a web manager, and target the profile section. By sending specially crafted input to the pet profile endpoint, they could inject malicious SQL commands into the database. This could lead to the compromise of sensitive information and disruption of the application's services.

  • Unauthenticated access to the web application.
  • Inputting malicious SQL into the pet profile parameter.
  • Database compromise and service disruption.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to execute arbitrary SQL commands by manipulating the `id_pet` parameter in the `/pet/profile_pet.php` endpoint. This could lead to unauthorized access to, modification of, or deletion of database information.

  • Database information is at risk.
  • Attackers can inject SQL commands remotely.
  • Data confidentiality, integrity, and availability may be compromised.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that WeGIA is a web manager for charitable institutions, the application owners or the platform team responsible for its deployment are likely to have ownership of this vulnerability. The first practical step is to identify all instances of WeGIA within the organization, confirm their network exposure and criticality, and then assign an owner for remediation.

  • Application or platform team owns the issue.
  • Verify network exposure and asset criticality.
  • Plan risk-based remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WeGIA?

WeGIA is an open-source web-based management platform built to help charitable institutions organize their operations. It serves as a central hub for managing organizational data, including pet profiles, through a web interface that runs on a server and is accessed by users via standard web browsers.

What is the vulnerability in CVE-2025-61605?

This CVE involves an SQL Injection (CWE-89) weakness. In simple terms, the application does not properly sanitize input provided by users. This allows a malicious actor to inject their own database commands into the system, which the application then unintentionally runs against its own database.

How does an attacker trigger this SQL injection?

An attacker targets the /pet/profile_pet.php endpoint by manipulating the id_pet parameter. The vulnerability is specific to this input field; interactions that do not involve sending crafted input to this particular parameter are not the primary path for this specific exploit.

How do I know if my organization is at risk?

According to Halo Surface Signal, WeGIA is typically deployed as a web service accessible over a network. If your instance is reachable via the internet or an intranet, it is accessible to potential attackers, increasing the relevance of this vulnerability to your security posture.

What is the first step to remediate this issue?

Your initial priority is to inventory your environment to locate all running instances of WeGIA. Once identified, verify their network accessibility and determine the business criticality of the data they hold. You should then schedule an update to version 3.5.0 or later to patch the vulnerability.

References