Path traversal in WeGIA - CVE-2025-55169
Published: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in the html/socio/sistema/download_remessa.php endpoint when processing the file parameter. A remote attacker can send a specially crafted request to disclose sensitive information.
The endpoint can be accessed without authentication, and exposed files may include config.php and other local system files.