Missing Authorization in WeGIA - #VU136995

 

Missing Authorization in WeGIA - #VU136995

Published: July 7, 2026


Vulnerability identifier: #VU136995
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to modify payment information.

The vulnerability exists due to missing authorization in atualiza_pagamentos.php when handling payment status update requests. A remote attacker can send a specially crafted request to modify payment information.

The issue can be exploited without authentication to mark arbitrary payment records as paid.


Affected software

WeGIA

Remediation

Install security update from vendor's website.

WeGIA - update to 3.8.7

External References

Related Security Bulletins