WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the upload of malicious files, such as .phar, which can then be executed by the server. This vulnerability is fixed in 3.2.8.
References
Link | Resource |
---|---|
https://github.com/nilsonLazarin/WeGIA/commit/a08f04de96d3caec85496d7a89a5b82d1960d9dd | Patch |
https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-mjgr-2jxv-v8qf | Exploit Third Party Advisory |
https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-mjgr-2jxv-v8qf | Exploit Third Party Advisory |
Configurations
History
09 Apr 2025, 18:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/nilsonLazarin/WeGIA/commit/a08f04de96d3caec85496d7a89a5b82d1960d9dd - Patch | |
References | () https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-mjgr-2jxv-v8qf - Exploit, Third Party Advisory | |
CPE | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* | |
First Time |
Wegia
Wegia wegia |
08 Jan 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-mjgr-2jxv-v8qf - |
07 Jan 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-07 22:15
Updated : 2025-04-09 18:29
NVD link : CVE-2025-22133
Mitre link : CVE-2025-22133
CVE.ORG link : CVE-2025-22133
JSON object : View
Products Affected
wegia
- wegia