Vulnerabilities
Vulnerable Software
Wegia:  >> Wegia  >> 3.6.5  Security Vulnerabilities
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator accounts, modify existing passwords, or execute any database operation. This was introduced in commit 370104c. This issue was patched in version 3.6.7.
CVSS Score
8.6
EPSS Score
0.001
Published
2026-03-20
WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted contents. Neither the extraction nor the file reading validates whether archive members are symbolic links. This vulnerability is fixed in 3.6.6.
CVSS Score
6.9
EPSS Score
0.001
Published
2026-03-11


Contact Us

Shodan ® - All rights reserved