eGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows unauthenticated users to access protected application functionalities and retrieve sensitive information by sending crafted HTTP requests without any session cookies or authentication tokens. Version 3.4.5 fixes the issue.
| Link | Resource |
|---|---|
| https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj | Exploit Vendor Advisory |
| https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj | Exploit Vendor Advisory |
25 Jul 2025, 16:37
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Wegia
Wegia wegia |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj - Exploit, Vendor Advisory | |
| CPE | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
18 Jul 2025, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-6p76-7mm4-j5rj - |
17 Jul 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
16 Jul 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Published : 2025-07-16 16:15
Updated : 2025-07-25 16:37
NVD link : CVE-2025-53938
Mitre link : CVE-2025-53938
CVE.ORG link : CVE-2025-53938
JSON object : View
Missing Authentication for Critical Function