Missing Authorization in WeGIA - #VU136978
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify payment records and mark payments as paid.
The vulnerability exists due to missing authorization in atualiza_pagamentos.php when handling unauthenticated POST requests to the payment update endpoint. A remote attacker can send a specially crafted request to modify payment records and mark payments as paid.