LabRedesCefetRJ WeGIA是LabRedesCefetRJ组织的一款整合文件管理与其他企业应用的软件。 LabRedesCefetRJ WeGIA 3.9.2之前版本存在授权问题漏洞,该漏洞源于员工资料页面存在不安全的直接对象引用,已认证攻击者可通过请求提取函数注入id_pessoa参数以覆盖会话派生标识符,从而访问任意员工记录,可能导致攻击者枚举所有用户标识,获取包括姓名、CPF、地址、联系方式和管理员标志在内的完整个人资料。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| LabRedesCefetRJ | WeGIA | < 3.9.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LabRedesCefetRJ | WeGIA | 0 ~ 3.9.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet