PT-2026-22413 · Wegia · Wegia

Hunterxsirago1

·

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-28411

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.5
Description WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the extract() function on the $ REQUEST superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This can bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. The extract() function is a PHP function that converts variables from an array to individual variables. The $ REQUEST superglobal contains data from GET, POST, and COOKIE requests.
Recommendations Update WeGIA to version 3.6.5.

Exploit

Fix

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28411
GHSA-G7R9-HXC8-8VH7

Affected Products

Wegia