WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows unauthenticated users to access protected application functionalities and retrieve sensitive information by sending crafted HTTP requests without any session cookies or authentication tokens. Version 3.4.5 fixes the issue.
References
Link | Resource |
---|---|
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj | Exploit Vendor Advisory |
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj | Exploit Vendor Advisory |
Configurations
History
25 Jul 2025, 16:37
Type | Values Removed | Values Added |
---|---|---|
First Time |
Wegia wegia
Wegia |
|
CPE | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* | |
References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj - Exploit, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
18 Jul 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj - |
17 Jul 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
16 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-16 16:15
Updated : 2025-07-25 16:37
NVD link : CVE-2025-53938
Mitre link : CVE-2025-53938
CVE.ORG link : CVE-2025-53938
JSON object : View
Products Affected
wegia
- wegia
CWE
CWE-306
Missing Authentication for Critical Function