Missing Authorization in WeGIA - #VU136979
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify member personal data.
The vulnerability exists due to missing authorization in processa_edicao_socio.php when handling unauthenticated requests to the member edit endpoint. A remote attacker can send a specially crafted request to overwrite member information to modify member personal data.