Missing Authorization in WeGIA - #VU136995
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify payment information.
The vulnerability exists due to missing authorization in atualiza_pagamentos.php when handling payment status update requests. A remote attacker can send a specially crafted request to modify payment information.
The issue can be exploited without authentication to mark arbitrary payment records as paid.