Improper Authentication in WeGIA - CVE-2025-55171
Published: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper authentication in /html/personalizacao_remover.php when handling crafted POST requests with the imagem_0 parameter. A remote attacker can send a specially crafted request to cause a denial of service.
By brute-forcing image identifiers, it is possible to delete image files, while the default file with imagem_id = 1 is not deleted.