Executive brief
WeGIA, a web-based management system for charitable institutions, contains a security flaw where it reveals too much technical information in error messages. When certain pages are accessed, the system displays internal database details and server configurations to any user. This information could be used by a malicious actor to better understand the system's internal structure and plan more sophisticated attacks.
Technical details
A sensitive information disclosure vulnerability exists in WeGIA versions prior to 3.7.0 due to improper error handling in the 'atendido/familiar_docfamiliar.php' component. The application returns overly verbose error messages that include database-related details and implementation specifics. An unauthenticated remote attacker can trigger these errors to leak information such as permitted file extensions, buffer sizes, or specific image processing libraries. This data facilitates reconnaissance and the development of targeted payloads to bypass security filters. The issue is addressed in version 3.7.0.
Affected products
- LabRedesCefetRJ WeGIA < 3.7.0
Timeline
- 2026-04-24: advisory: GitHub Security Advisory published by maintainers
- 2026-05-11: disclosed: CVE-2026-42871 published to NVD