CyberRota Analysis
AI-GeneratedThe WeGIA web manager for charitable institutions prior to version 3.8.5 contains a critical vulnerability that exposes an unauthenticated GET endpoint, allowing remote attackers to exploit a hardcoded parameter to perform TRUNCATE TABLE operations on key database tables. This can lead to the permanent deletion of member and contributor records without requiring administrative access. Organizations using affected versions should prioritize upgrading to 3.8.5 to mitigate the risk of data loss.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafisica, pessoajuridica, and socio tables without an administrative session or application authorization, permanently destroying member and contributor records. The attack requires the affected tables to exist and the web process database account to possess truncation privileges. This issue is fixed in version 3.8.5.