Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2026-28411
9.8CRITICAL
What is CVE-2026-28411?
The WeGIA Web Manager for charitable institutions contains a vulnerability due to the unsafe usage of the extract() function on the $_REQUEST superglobal. This flaw permits unauthenticated attackers to overwrite local variables across multiple PHP scripts, which can lead to unauthorized access and a complete bypass of authentication checks, allowing attackers to gain entry to sensitive administrative and protected areas of the application. The issue is addressed in version 3.6.5.
Affected Version(s)
WeGIA < 3.6.5
