Report: CVE-2026-40285 - WeGIA has SQL Injection via Session Variable Override in DespachoControle.php

Report: CVE-2026-40285 - WeGIA has SQL Injection via Session Variable Override in DespachoControle.php

CVE ID :CVE-2026-40285 Published : April 17, 2026, 8:25 p.m. | 1 hour ago Description :WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the attacker-controlled value is then interpolated directly into a raw SQL query, allowing any authenticated user to query the database under an arbitrary identity. Version 3.6.10 fixes the issue. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
April 17, 2026
Affected Product: php
Impact: SQL injection