Home

Description

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and financial information of members without requiring authentication or authorization. This issue is fixed in version 3.5.0.

PUBLISHED Reserved 2025-09-29 | Published 2025-10-02 | Updated 2025-10-03 | Assigner GitHub_M




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-287: Improper Authentication

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

< 3.5.0
affected

References

github.com/.../WeGIA/security/advisories/GHSA-62wp-6qmh-6p5f

github.com/...ommit/828f23a6a760a52b8bb8bfd583cc2b23c42da51e

cve.org (CVE-2025-61665)

nvd.nist.gov (CVE-2025-61665)

Download JSON