Executive brief
WeGIA, a web-based management platform for charitable institutions, contains a security flaw that allows attackers to redirect users to malicious websites. By tricking an administrator into clicking a specially crafted link, an attacker can make a malicious site appear as a legitimate follow-up to a successful system action, such as a database backup. This can be used in phishing campaigns to steal login credentials or distribute malware while leveraging the trust of the institution's own domain.
Technical details
An open redirect vulnerability exists in WeGIA versions prior to 3.6.9 due to insufficient validation of the 'redirect' GET parameter in 'html/configuracao/backup.php'. The application retrieves the URL directly from the user input and passes it to the PHP header() function without checking against a whitelist or validating the destination. An attacker can exploit this by crafting a URL that, upon completion of a backup task, redirects an authenticated administrator to an external, attacker-controlled domain. This vulnerability is classified as CWE-601 and requires minimal user interaction (clicking a link) to execute. The issue is resolved in version 3.6.9.
Affected products
- LabRedesCefetRJ WeGIA < 3.6.9
Timeline
- 2026-04-02: advisory: GitHub Security Advisory published by vendor
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Fix released in version 3.6.9