Path traversal in WeGIA - CVE-2025-55169

 

Path traversal in WeGIA - CVE-2025-55169

Published: April 30, 2026


Vulnerability identifier: #VU128673
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-55169
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in the html/socio/sistema/download_remessa.php endpoint when processing the file parameter. A remote attacker can send a specially crafted request to disclose sensitive information.

The endpoint can be accessed without authentication, and exposed files may include config.php and other local system files.


Affected software

WeGIA

How to mitigate CVE-2025-55169

Install security update from vendor's website.

WeGIA - update to 3.4.8

External References

Related Security Bulletins