CVE-2025-27140
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions pri
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, importar_dump.php endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely.
The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.
CRITICAL · CVSS 9.8
EPSS 0.02205
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0