Improper Authentication in WeGIA - CVE-2025-61665

 

Improper Authentication in WeGIA - CVE-2025-61665

Published: April 23, 2026


Vulnerability identifier: #VU127275
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-61665
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper authentication in get_relatorios_socios.php endpoint when handling crafted GET requests to the member reports endpoint. A remote attacker can send a specially crafted request to disclose sensitive information.

Exposed data may include full names, phone numbers, CPF numbers, financial amounts, email addresses, and membership status.


Affected software

WeGIA

How to mitigate CVE-2025-61665

Install security update from vendor's website.

WeGIA - update to 3.5.0

External References

Related Security Bulletins