CVE-2025-58745 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA on…
Critical CVSS: 9.9

CVE-2025-58745

WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at endpoint `/html/socio/sistema/controller/controla_xlsx.php`, which can be bypassed by using magic bytes of Excel file in a PHP file. As a result, attacker can upload webshell to the server for remote code execution. Version 3.4.11 contains an updated fix.
Vendor
Wegia
Product
Wegia
CWE
CWE-94
Yayın Tarihi
2025-09-08 23:15:35
Güncelleme
2025-09-17 16:24:10
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar