Impact
WeGIA maps the InternoControle module to an empty resource array before version 3.8.5, and the permission verifier treats that array as granting unconditional access to any authenticated user. Consequently, methods such as listarUm, alterar, and excluir accept user supplied identifiers without checking record ownership, enabling a low‑privileged user to read, modify, or delete another individual's personal, identity, address, medical, and family information.
Affected Systems
This vulnerability affects the WeGIA web management platform developed by LabRedesCefetRJ. All deployed instances running any release prior to version 3.8.5 are susceptible; the issue was fixed in the 3.8.5 release and later versions.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score is reported as less than 1 %, suggesting a low probability of exploitation at the time of analysis, and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated session; a low‑privileged user can trigger the affected endpoints to gain unauthorized data disclosure and modification. Because the flaw relies on empty‑resource authorization, there is no requirement for special network‑level access beyond normal login credentials.
OpenCVE Enrichment