CRITICAL
9.1 CVE-2026-54670 Published 17 Sept 2026
WeGIA Web Manager Unauthenticated Access Vulnerability
Worried this affects your website?
WeGIA, a web manager for charitable institutions, is affected. Prior to version 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled 'nomeClasse' and 'metodo' values without proper validation, allowing unauthenticated remote attackers to invoke sensitive methods and expose contribution records or trigger financial workflow operations.
Additionally, a traversal-shaped 'nomeClasse' value can cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing sensitive data.
- Versions affected: Prior to 3.8.5
- Impact: Unauthenticated access to sensitive data and operations
Reference: CVE-2026-54670 on NVD
← Back to Security News