WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and allows unauthorized attackers to bypass authentication and authorization mechanisms to reset the password of any user, including admin accounts. Version 3.2.6 fixes the issue.
History

Thu, 10 Apr 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Wegia
Wegia wegia
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
Vendors & Products Wegia
Wegia wegia
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 27 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description WeGIA is a Web manager for charitable institutions. A security vulnerability was identified in versions prior to 3.2.6, where it is possible to change a user's password without verifying the old password. This issue exists in the control.php endpoint and allows unauthorized attackers to bypass authentication and authorization mechanisms to reset the password of any user, including admin accounts. Version 3.2.6 fixes the issue.
Title WeGIA Vulnerable to Broken Authentication - Old Password Validation
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:L/SI:H/SA:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-03-27T18:49:27.739Z

Reserved: 2025-03-21T14:12:06.271Z

Link: CVE-2025-30361

cve-icon Vulnrichment

Updated: 2025-03-27T18:49:23.378Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-27T17:15:57.167

Modified: 2025-04-10T15:16:33.707

Link: CVE-2025-30361

cve-icon Redhat

No data.