CVE-2025-55169

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

History

14 Aug 2025, 01:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/LabRedesCefetRJ/WeGIA/commit/e8476168171de2f3e047ed92bbc264c981b416b1 - () https://github.com/LabRedesCefetRJ/WeGIA/commit/e8476168171de2f3e047ed92bbc264c981b416b1 - Patch
References () https://github.com/LabRedesCefetRJ/WeGIA/issues/177 - () https://github.com/LabRedesCefetRJ/WeGIA/issues/177 - Issue Tracking, Mitigation
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-mm3p-7573-4x4j - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-mm3p-7573-4x4j - Exploit, Vendor Advisory
CPE cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
First Time Wegia wegia
Wegia

13 Aug 2025, 17:33

Type Values Removed Values Added
Summary
  • (es) WeGIA es un gestor web de código abierto centrado en el idioma portugués y las instituciones benéficas. Antes de la versión 3.4.8, se descubrió una vulnerabilidad de path traversal en el endpoint html/socio/sistema/download_remessa.php de la aplicación WeGIA. Esta vulnerabilidad podría permitir a un atacante obtener acceso no autorizado a archivos locales del servidor e información confidencial almacenada en config.php. config.php contiene información que podría permitir el acceso directo a la base de datos. Este problema se ha corregido en la versión 3.4.8.

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-14 01:30


NVD link : CVE-2025-55169

Mitre link : CVE-2025-55169

CVE.ORG link : CVE-2025-55169


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-287

Improper Authentication