PT-2026-22413 · Wegia · Wegia

Hunterxsirago1

·

Publicado

2026-02-27

·

Atualizado

2026-03-04

·

CVE-2026-28411

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.5
Description WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the extract() function on the $ REQUEST superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This can bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. The extract() function is a PHP function that converts variables from an array to individual variables. The $ REQUEST superglobal contains data from GET, POST, and COOKIE requests.
Recommendations Update WeGIA to version 3.6.5.

Exploit

Correção

Authentication Bypass Using an Alternate Path or Channel

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28411
GHSA-G7R9-HXC8-8VH7

Produtos afetados

Wegia