PT-2026-22413 · Wegia · Wegia
Hunterxsirago1
·
Published
2026-02-27
·
Updated
2026-03-04
·
CVE-2026-28411
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
WeGIA versions prior to 3.6.5
Description
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the
extract() function on the $ REQUEST superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This can bypass authentication checks, allowing unauthorized access to administrative and protected areas of the WeGIA application. The extract() function is a PHP function that converts variables from an array to individual variables. The $ REQUEST superglobal contains data from GET, POST, and COOKIE requests.Recommendations
Update WeGIA to version 3.6.5.
Exploit
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wegia