WeGIA 是一款面向慈善机构使用的 Web 管理系统。在 3.8.5 版本之前,WeGIA 在 文件中将 映射到一个空的资源数组;而 中的 函数将该空数组视为对所有已认证用户无条件授予访问权限。 中的方法(包括 、 和 )接受用户控制的 或 值,但未验证资源所有权,导致权限较低的用户可以读取、修改或删除他人的记录,从而暴露个人身份信息、地址、医疗及家庭等敏感数据。 安全公告指出,在报告的版本中,存在一个自我引用的加载 bug,可能导致该控制器崩溃;但空资源授权模式以及受影响的方法仍被视为当前审查的核心漏洞。该问题
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LabRedesCefetRJ | WeGIA | < 3.8.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54767 | 9.1 CRITICAL | WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php |
| CVE-2026-54670 | 9.1 CRITICAL | WeGIA: Unauthenticated Auth Bypass + Local File Inclusion |
No comments yet