Missing Authentication for Critical Function in WeGIA - CVE-2025-53938
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication in multiple endpoint handlers when handling crafted HTTP requests without any session cookies or authentication tokens. A remote attacker can send crafted HTTP requests to disclose sensitive information.
The issue affects /dao/verificar_recursos_cargo.php, /dao/exibir_cargo.php, /dao/verificar_modulos_visiveis.php, /dao/exibir_documento.php, and /dao/adicionar_documento.php.