← Back to browse · API

CVE-2025-55169

Severity
CRITICAL
CVSS
10.0
EPSS
0.01552
Risk score
40.54
CISA KEV
No
PoC
No
Published
2025-08-12
Modified
2025-08-12
First seen
2026-08-07
Aliases
EUVD-2025-24455
Products
LabRedesCefetRJ:WeGIA < 3.4.8
Sources
euvd EUVD-2025-24455

Description

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.

References