Information Disclosure in WeGIA Web Manager for Charitable Institutions
CVE-2026-42873

NONE

Key Information:

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-42873?

The WeGIA web manager for charitable institutions has a vulnerability that allows the upload of files with malicious content to the funcionario/docdependente_upload.php endpoint. In versions prior to 3.6.10, this leads to the application generating overly descriptive error messages when file uploads fail. These messages unintentionally disclose sensitive technical information, increasing the risk of exploitation by potential attackers. The vulnerability was addressed in version 3.6.10, which mitigates the risk of information leaks and strengthens the overall security of the application.

Affected Version(s)

WeGIA < 3.6.10

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.