PT-2025-29867 · Wegia · Wegia

Marcelomulder

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53938

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description An authentication bypass issue exists in the /dao/verificar recursos cargo.php API endpoint of the WeGIA application. This allows unauthenticated users to access protected functionalities and retrieve sensitive information by sending crafted HTTP requests without valid session cookies or authentication tokens.
Recommendations Update to version 3.4.5 or later.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-09274
CVE-2025-53938
GHSA-6P76-7MM4-J5RJ

Affected Products

Wegia