Report: CVE-2026-35395 - WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter - Analysis
CVE ID :CVE-2026-35395 Published : April 6, 2026, 9:16 p.m. | 14 minutes ago Description :WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in dao/memorando/DespachoDAO.php. The id_memorando parameter is extracted from $_REQUEST without validation and directly interpolated into SQL queries, allowing any authenticated user to execute arbitrary SQL commands against the database. This vulnerability is fixed in 3.6.9. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...