Impact
WeGIA prior to version 3.9.2 contains an insecure direct object reference flaw in the employee profile page. The flaw allows an authenticated attacker to submit a crafted id_pessoa parameter that overrides the session‑derived identifier. By enumerating valid identifiers, the attacker can retrieve full profile data for any employee, including name, CPF, address, contact details and administrative flags.
Affected Systems
The vulnerability affects the WeGIA application produced by LabRedesCefetRJ. All releases before 3.9.2 are impacted; the fix is included in 3.9.2 and later versions.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity, and the lack of an EPSS score means the exploitation likelihood cannot be quantified from the data. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated to the system, and the attack vector is a web request to the profile page; the flaw is likely exposed to any user with valid credentials who can supply arbitrary id_pessoa values. Given the sensitivity of the data exposed, the risk remains significant for any organization using affected WeGIA releases.
OpenCVE Enrichment