CVE-2025-53938
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authenticati
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows unauthenticated users to access protected application functionalities and retrieve sensitive information by sending crafted HTTP requests without any session cookies or authentication tokens.
Version 3.4.5 fixes the issue.
HIGH · CVSS 7.5
EPSS 0.00207
Act now
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0