Improper Authentication in WeGIA - CVE-2025-61665
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper authentication in get_relatorios_socios.php endpoint when handling crafted GET requests to the member reports endpoint. A remote attacker can send a specially crafted request to disclose sensitive information.
Exposed data may include full names, phone numbers, CPF numbers, financial amounts, email addresses, and membership status.