CVE-2025-26616
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information stored in `config.php`. `config.php` contains information that could allow direct access to the database. This issue has been addressed in version 3.2.14 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 0.66%
- CWE
- CWE-22, CWE-284
- Published
- 2025-02-18
- Last modified
- 2026-03-13
Affected products
- LabRedesCefetRJ WeGIA
Weakness type
Related vulnerabilities
- CVE-2026-88046 — rclone: source object names can escape the configured root on upload
- CVE-2026-88014 — rclone archive/zip: Zip Slip via unsanitized zip entry names lets a malicious archive escape its own namespace
- CVE-2026-88940 — knowns through 0.33.0 Arbitrary Directory Enumeration via workspace browse endpoint
- CVE-2026-88938 — knowns through 0.33.0 Path Traversal via code.find MCP tool
- CVE-2026-88937 — knowns through 0.33.0 Path Traversal via Template Engine
- CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability
- CVE-2026-81275 — WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability
- CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal