CVE-2025-55171
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-08-12

Last updated on: 2025-08-14

Assigner: GitHub, Inc.

Description
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not check authentication at endpoint /html/personalizacao_remover.php allowing anonymous attacker (without login) to delete any Image files at endpoint /html/personalizacao_remover.php by defining imagem_0 as image id to delete. This issue has been patched in version 3.4.8.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-08-12
Last Modified
2025-08-14
Generated
2026-05-27
AI Q&A
2025-08-12
EPSS Evaluated
2026-05-25
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wegia wegia to 3.4.8 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in WeGIA versions prior to 3.4.8 where the application does not check for user authentication at the endpoint /html/personalizacao_remover.php. This allows an anonymous attacker, without logging in, to delete any image files by specifying the image ID (imagem_0) to delete at that endpoint.


How can this vulnerability impact me? :

An attacker can delete image files without authentication, potentially causing denial of service or loss of important image data managed by the application.


What immediate steps should I take to mitigate this vulnerability?

Upgrade the WeGIA application to version 3.4.8 or later, as this version includes a patch that enforces authentication checks on the /html/personalizacao_remover.php endpoint, preventing anonymous deletion of image files.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart