PT-2026-24796 · Labredescefetrj+2 · Wegia

Exploitintel

·

Published

2026-03-11

·

Updated

2026-03-11

·

CVE-2026-31894

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.6
Description WeGIA is a web manager for charitable institutions. The loadBackupDB() function in version 3.6.5 extracts tar.gz archives to a temporary directory using PHP’s PharData class, then uses glob() and file get contents() to read SQL files from the extracted contents. The extraction and file reading processes do not validate whether archive members are symbolic links. This could allow for unauthorized file access or modification.
Recommendations Upgrade to WeGIA version 3.6.6 or later.

Exploit

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2026-31894
GHSA-6MMM-27H8-8G55

Affected Products

Wegia