Path traversal in WeGIA - CVE-2026-54670
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in web/html/contribuicao/controller/control.php when processing the nomeClasse parameter in POST requests to /html/contribuicao/controller/control.php. A remote attacker can supply a crafted controller path to disclose sensitive information.
The issue can be exploited without authentication, and included files may expose configuration data and PHP source files.