Executive brief
WeGIA is a web-based management system used by charitable institutions. A security flaw in the file upload component allows the system to reveal detailed technical error messages when a user attempts to upload a file. While not directly granting access to data, this information disclosure provides attackers with technical insights into the server's internal configuration, which could be used to plan more sophisticated attacks.
Technical details
An information disclosure vulnerability exists in WeGIA versions prior to 3.6.10 due to improper error handling in the 'funcionario/docdependente_upload.php' component. When a user with low-level privileges attempts to upload a file containing malicious content, the application returns verbose error messages instead of generic responses. These messages can leak sensitive implementation details such as permitted file extensions, buffer sizes, or specific image processing libraries in use. This technical footprinting allows an attacker to refine exploits or bypass security filters. The issue is addressed in version 3.6.10.
Affected products
- LabRedesCefetRJ WeGIA < 3.6.10
Timeline
- 2026-04-24: advisory: Original GitHub security advisory published
- 2026-05-11: disclosed: CVE published to NVD dataset
- 2026-05-11: patched: Fix released in version 3.6.10