PT-2025-35328 · Wegia · Wegia

Farinap5

·

Published

2025-08-29

·

Updated

2025-08-30

·

CVE-2025-58159

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.11
Description WeGIA is a Web manager for charitable institutions. A remote code execution issue was identified due to improper validation of uploaded files. The application allows attackers to upload files with arbitrary filenames, including those with a .php extension. Uploaded files are written to disk without adequate sanitization or extension restrictions, allowing a spreadsheet file followed by PHP code to be uploaded and executed on the server, leading to arbitrary code execution.
Recommendations Upgrade to version 3.4.11 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-58159
GHSA-WJ2C-237G-CGQP

Affected Products

Wegia