Missing Authentication for Critical Function in WeGIA - CVE-2026-28408
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to inject unauthorized data.
The vulnerability exists due to improper access control in adicionar_tipo_docs_atendido.php when handling direct requests to the file URL. A remote attacker can send a specially crafted request to inject unauthorized data.
The script does not go through the project's central controller, allowing access to features exclusive to employees.