Impact
The vulnerability arises from a lack of input validation for the 'nomeClasse' and 'metodo' parameters in the contribution dispatcher script. An unauthenticated user can trigger sensitive actions such as getContribuicoesLogJSON, sincronizarStatus, and registrarFaturas without proper authentication, leading to disclosure of donation records or unauthorized financial workflow executions. In addition, the traversal‑shaped 'nomeClasse' value allows an attacker to include arbitrary PHP or configuration files outside the intended controller directory, exposing source code, credentials, or other sensitive data.
Affected Systems
WeGIA hosted by LabRedesCefetRJ is impacted before version 3.8.5. Users running any release older than 3.8.5 are potentially vulnerable to authentication bypass and local file inclusion attacks through the web/HTML contrib frame.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity of the flaw. However, the EPSS score of less than 1% suggests that exploitation attempts are currently rare. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely via the web interface, sending crafted HTTP requests to the security‑critical control script without needing prior authentication or special privileges.
OpenCVE Enrichment