External risk intelligence

WeGIA SQL Injection Vulnerability in dependente_documento.php.

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2025-62360

WeGIA is a web-based management application designed for institutions. Such applications are typically deployed as internet-facing or intranet-facing web services accessed via browsers. Because it is a web application meant for organizational management, it is commonly deployed in environments reachable via network interfaces, making the web surface likely to be exposed to authorized users over the network.

SQL Injection

Wegia

before 3.5.1

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in the WeGIA web management tool, affecting its ability to protect institutional data. This vulnerability could allow unauthorized access and manipulation of sensitive information stored within the system.

  • Critical flaw in web manager affects data security.
  • High-impact vulnerability needs executive awareness.
  • Confirm WeGIA relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access could target the WeGIA application through its network interface. By interacting with the `/html/funcionario/dependente_documento.php` endpoint, they could manipulate the `id_dependente` parameter to inject malicious SQL commands. This could lead to unauthorized access and modification of sensitive data stored in the application's database.

  • Authenticated access required.
  • Manipulating `id_dependente` parameter.
  • Database compromise, data theft, or destruction.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, the `id_dependente` parameter in the `/html/funcionario/dependente_documento.php` endpoint could allow an authenticated attacker to execute arbitrary SQL commands. This could affect the confidentiality, integrity, and availability of the database.

  • Database confidentiality and integrity.
  • Authenticated SQL command execution.
  • Compromised institutional data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WeGIA application, specifically versions prior to 3.5.1, contains a critical SQL injection vulnerability. Given its nature as a web manager for institutions, ownership likely resides with platform or application teams responsible for hosting and managing the WeGIA instances. The first practical step is to identify all deployments, assess their network exposure and business criticality, and then confirm the accountable owner for remediation planning.

  • Platform/Application teams likely own this.
  • Verify all WeGIA instances and their exposure.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WeGIA and what do people use it for?

WeGIA is an open-source web-based management platform designed to help institutions handle administrative tasks. It is primarily built to serve Portuguese-language users and centralizes data handling through a web interface. By acting as a digital hub for institutional record-keeping, it allows users to manage various organizational documents and functions directly through their browsers.

What does SQL Injection mean for CVE-2025-62360?

This vulnerability is classified as CWE-89, or SQL Injection. It occurs when a web application improperly handles user input, allowing an attacker to inject and execute their own database commands. In this specific case, it lets unauthorized actors interact directly with the underlying database, potentially bypassing security controls to read, modify, or delete the institutional information stored within it.

How does an attacker trigger this vulnerability?

To trigger the bug, an attacker must interact with the specific /html/funcionario/dependente_documento.php endpoint and manipulate the id_dependente parameter. This requires the attacker to have already established authenticated access to the application. Requests that do not target this specific parameter or the designated script file will not trigger this particular SQL injection flaw.

Is my instance at risk according to Halo Surface Signal?

Halo Surface Signal indicates that because WeGIA is a web-based management tool, it is commonly deployed as an internet-facing or intranet-facing service. Since these applications are designed to be accessible via network interfaces for organizational use, the surface is likely exposed. You should consider your instance at risk if it is reachable over your network and currently running a version older than 3.5.1.

What is the first step to address this CVE-2025-62360 issue?

The most important first step is to locate and inventory every WeGIA instance running in your environment. Once you have identified all deployments, confirm which ones are currently below version 3.5.1. After documenting your assets and their respective network reach, coordinate with the technical teams managing those specific servers to prioritize and apply the update to version 3.5.1, which resolves the flaw.

References