PT-2025-7212 · Wegia · Wegia

Chan-Woong

+1

·

Published

2025-02-18

·

Updated

2025-05-04

·

CVE-2025-26613

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.2.14
Description: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, gerenciar backup.php endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely.
Recommendations: For versions prior to 3.2.14, upgrade to version 3.2.14 to address the issue. As a temporary workaround, consider restricting access to the gerenciar backup.php endpoint until the upgrade is applied. There are no known workarounds for this vulnerability.

Exploit

Fix

RCE

Improper Access Control

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-26613
GHSA-G3W6-M6W8-P6R2

Affected Products

Wegia