LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-33133

wegia · wegia

Published
CVSS7.2
Severityhigh
WeaknessCWE-89
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator accounts, modify existing passwords, or execute any database operation. This was introduced in commit 370104c. This issue was patched in version 3.6.7.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-33133

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-33133.