Impact
The flaw allows a remote attacker who discovers the hard‑coded secret key in the public source to invoke a vulnerable HTTP GET endpoint, deletar_socios.php, without needing any authentication. The endpoint then executes TRUNCATE TABLE statements on the endereco, pessoafisica, pessoajuridica, and socio tables, permanently deleting all member and contributor records. The exploitation requires only that the affected tables exist and that the database account used by the web process has TRUNCATE privileges. The impact is the irreversible loss of critical organisational data.
Affected Systems
The vulnerability affects installations of the WeGIA web manager for charitable institutions from all release versions prior to 3.8.5. The vendor is LabRedesCefetRJ, and the affected component is the deletar_socios.php controller within the web/html/socio/sistema directory.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity vulnerability, and the EPSS score of less than 1% implies a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. Because the secret key is embedded in the public code repository, the likely attack vector is an unauthenticated remote HTTP request, and discovery of the key is trivial. Successful exploitation yields complete data loss without administrative access or application authorisation.
OpenCVE Enrichment