Executive brief
WeGIA is a web application used by charitable institutions to manage internal operations and staff data. A critical flaw in the access control mechanism allows low-privileged employees to read, modify, or delete records belonging to other users without authorization, exposing sensitive personal, medical, identity, and family information. An attacker can exploit this by manipulating user IDs in requests to gain unauthorized access to confidential data.
Technical details
The vulnerability exists in how WeGIA's MiddlewareDAO.php handles permission checks: it maps certain controllers (including InternoControle) to an empty resource array, which the verificarPermissao() function incorrectly treats as granting unconditional access to all authenticated users. The affected methods (listarUm, alterar, excluir) in InternoControle.php accept user-controlled id and idInterno parameters without verifying that the requesting user owns or has permission to access those records. The attack requires authentication but no elevated privileges; a low-privileged user can directly request other users' records via manipulated IDs. This results in unauthorized data exposure and modification. The vulnerability is fixed in WeGIA version 3.8.5.
Affected products
- LabRedesCefetRJ WeGIA prior to 3.8.5
Timeline
- 2026-09-17: disclosed
- 2026-09-17: patched: Fixed in version 3.8.5