Cross-site request forgery in WeGIA - CVE-2025-61604
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to perform unauthorized deletion actions.
The vulnerability exists due to cross-site request forgery in the AlmoxarifadoControle class delete functionality on the control.php endpoint when handling crafted GET requests. A remote user can trick a victim into visiting a crafted page or link to perform unauthorized deletion actions.
User interaction is required to trigger the crafted request.