Description
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not check authentication at endpoint /html/personalizacao_remover.php allowing anonymous attacker (without login) to delete any Image files at endpoint /html/personalizacao_remover.php by defining imagem_0 as image id to delete. This issue has been patched in version 3.4.8.
Problem types
CWE-287: Improper Authentication
Product status
References
github.com/.../WeGIA/security/advisories/GHSA-8rm5-3jvx-hcxv
github.com/LabRedesCefetRJ/WeGIA/issues/109
github.com/...ommit/aa63f499a285bf91795b9836eec0425e7eafe570