PT-2025-40428 · Wegia · Wegia

Marcelomulder

·

Published

2025-10-02

·

Updated

2025-10-07

·

CVE-2025-61665

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.4.12 and below
Description WeGIA, a web manager for charitable institutions, has a Broken Access Control issue. The get relatorios socios.php API endpoint allows unauthenticated attackers to directly access sensitive personal and financial information of members without authentication or authorization.
Recommendations Update to version 3.5.0 or later.

Exploit

Fix

Improper Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-61665
GHSA-62WP-6QMH-6P5F

Affected Products

Wegia