CVE-2025-50201
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was identified in the /html/configuracao/debug_info.php endpoint. The branch parameter is not properly sanitized before being concatenated and executed in a shell command on the server's operating system. This flaw allows an unauthenticated attacker to execute arbitrary commands on the server with the privileges of the web server user (www-data). This issue has been patched in version 3.4.2.
Vendor
Product
CWE
Yayın Tarihi
2025-06-19 04:15:49
Güncelleme
2025-07-02 16:21:03
Source Identifier
security-advisories@github.com
KEV Date Added
-