Description
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5.
Published: 2026-09-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure & Unauthorized Operations
Action: Patch Now
AI Analysis

Impact

The vulnerability arises from a lack of input validation for the 'nomeClasse' and 'metodo' parameters in the contribution dispatcher script. An unauthenticated user can trigger sensitive actions such as getContribuicoesLogJSON, sincronizarStatus, and registrarFaturas without proper authentication, leading to disclosure of donation records or unauthorized financial workflow executions. In addition, the traversal‑shaped 'nomeClasse' value allows an attacker to include arbitrary PHP or configuration files outside the intended controller directory, exposing source code, credentials, or other sensitive data.

Affected Systems

WeGIA hosted by LabRedesCefetRJ is impacted before version 3.8.5. Users running any release older than 3.8.5 are potentially vulnerable to authentication bypass and local file inclusion attacks through the web/HTML contrib frame.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity of the flaw. However, the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely via the web interface, sending crafted HTTP requests to the security‑critical control script without needing prior authentication or special privileges.

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply release 3.8.5 or later of WeGIA to close the authentication bypass and LFI flaw
  • Configure the web server to require authentication for control.php and enforce directory confinement, e.g., using OpenBasedir or chroot
  • If the patch cannot be applied immediately, remove or comment out the vulnerable controller functions such as getContribuicoesLogJSON and other sensitive actions until the update is installed

Generated by OpenCVE AI on September 19, 2026 at 01:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Labredescefetrj
Labredescefetrj wegia
Vendors & Products Labredescefetrj
Labredescefetrj wegia

Thu, 17 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5.
Title WeGIA: Unauthenticated Auth Bypass + Local File Inclusion
Weaknesses CWE-22
CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Labredescefetrj Wegia
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-23T19:11:47.212Z

Reserved: 2026-06-15T22:53:58.560Z

Link: CVE-2026-54670

cve-icon Vulnrichment

Updated: 2026-09-23T19:11:20.183Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:02.983

Modified: 2026-09-23T20:17:11.267

Link: CVE-2026-54670

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-306

    Missing Authentication for Critical Function