WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and allows unauthorized attackers to bypass authentication and authorization mechanisms to reset the password of any user, including admin accounts. Version 3.2.6 fixes the issue.
CVSS
No CVSS.
References
Configurations
No configuration.
History
27 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-27 17:15
Updated : 2025-03-28 18:11
NVD link : CVE-2025-30361
Mitre link : CVE-2025-30361
CVE.ORG link : CVE-2025-30361
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication