CVE-2025-55169

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

History

14 Aug 2025, 01:30

Type Values Removed Values Added
First Time Wegia
Wegia wegia
CPE cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/LabRedesCefetRJ/WeGIA/commit/e8476168171de2f3e047ed92bbc264c981b416b1 - () https://github.com/LabRedesCefetRJ/WeGIA/commit/e8476168171de2f3e047ed92bbc264c981b416b1 - Patch
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-mm3p-7573-4x4j - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-mm3p-7573-4x4j - Exploit, Vendor Advisory
References () https://github.com/LabRedesCefetRJ/WeGIA/issues/177 - () https://github.com/LabRedesCefetRJ/WeGIA/issues/177 - Issue Tracking, Mitigation

12 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-12 19:15

Updated : 2025-08-14 01:30


NVD link : CVE-2025-55169

Mitre link : CVE-2025-55169


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-287

Improper Authentication