WeGIA是Nilson Lazarin个人开发者的一个福利机构的网络管理器。 WeGIA 3.4.8之前版本存在路径遍历漏洞,该漏洞源于/html/socio/sistema/download_remessa.php端点存在路径遍历,可能导致本地文件泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LabRedesCefetRJ | WeGIA | < 3.4.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-55169.yaml | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-55171 | 7.5 HIGH | WeGIA Anonymous Attacker can Delete Arbitrary Image file at endpoint `/html/personalizacao |
| CVE-2025-55170 | 6.5 MEDIUM | WeGIA reflected XSS via `verificacao` and `redir_config` param at endpoint `/html/alterar_ |
| CVE-2025-55167 | WeGIA SQL Injection via id_fichamedica at endpoint `GET/html/funcionario/dependente_remove | |
| CVE-2025-55168 | WeGIA SQL Injection via id_fichamedica at endpoint `GET /html/saude/aplicar_medicamento.ph |
No comments yet