Path traversal in WeGIA - CVE-2025-26616

 

Path traversal in WeGIA - CVE-2025-26616

Published: February 17, 2025 / Updated: May 2, 2026


Vulnerability identifier: #VU129023
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-26616
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to path traversal in the exportar_dump.php endpoint when processing the file parameter in POST requests. A remote attacker can send a specially crafted request to disclose sensitive information.

The issue can be exploited without being logged in because execution continues after the redirect code following session validation.


Affected software

WeGIA

How to mitigate CVE-2025-26616

Install security update from vendor's website.

WeGIA - update to 3.2.14

External References

Related Security Bulletins