Information Disclosure in WeGIA Web Manager for Charitable Institutions
CVE-2026-42873
NONE
What is CVE-2026-42873?
The WeGIA web manager for charitable institutions has a vulnerability that allows the upload of files with malicious content to the funcionario/docdependente_upload.php endpoint. In versions prior to 3.6.10, this leads to the application generating overly descriptive error messages when file uploads fail. These messages unintentionally disclose sensitive technical information, increasing the risk of exploitation by potential attackers. The vulnerability was addressed in version 3.6.10, which mitigates the risk of information leaks and strengthens the overall security of the application.
Affected Version(s)
WeGIA < 3.6.10
