S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 19, 2025

CVE-2025-55169 Scanner

CVE-2025-55169 Scanner - Path Traversal vulnerability in WeGIA

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.4k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-55169
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vulnerability was discovered in the WeGIA application, html/socio/sistema/download_remessa.php endpoint. This vulnerability could allow an attacker to gain unauthorized access to local files in the server and sensitive information stored in config.php. config.php contains information that could allow direct access to the database. This issue has been patched in version 3.4.8.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WeGIAby LabRedesCefetRJ
< 3.4.8
Updated Sep 9, 2026View on NVD →
Detail

WeGIA is an open-source web management system primarily used by Portuguese-speaking charitable institutions to manage various web-based resources. It is built to facilitate operations in organizations with a focus on providing an easy-to-use interface for managing online content and infrastructure. The software's design allows for flexibility and scalability, making it suitable for small to medium-sized entities that rely on web management systems for daily operations. WeGIA integrates several web applications that help charities streamline their processes and document handling. It is actively maintained and regularly receives updates and patches to address security concerns. The software supports multiple users and permission levels, ensuring that tasks are assigned and managed efficiently within the organization.

The identified vulnerability in WeGIA exposes the system to path traversal attacks. This allows an attacker to manipulate file paths, thus gaining unauthorized access to sensitive data stored within the server. Path traversal vulnerabilities are a result of inadequate input validation, which leads to exploitation, allowing directory traversal outside of the intended locations. WeGIA's failure in preventing such traversal can lead to significant security risks, as critical files like config.php may be exposed. These files contain sensitive information that could, for example, grant direct database access to malicious parties. Such vulnerabilities are critical as they undermine the system's data integrity and confidentiality.

Technical details about this vulnerability indicate that it can be exploited via the endpoint html/socio/sistema/download_remessa.php in the WeGIA application. Manipulating parameters allows attackers to navigate directories beyond the set bounds, reaching sensitive files such as config.php. This endpoint's improper validation makes it susceptible to unauthorized file reads. The config.php file includes crucial configuration details, including database credentials that can be exploited. Attackers can potentially access information that may lead to further breaches and a loss of data integrity. The vulnerability's critical nature demands prompt remediation measures.

Exploitation of this vulnerability leads to unauthorized disclosure of sensitive data, crippling the organization's security posture. Malicious actors gaining access to files like config.php can result in unauthorized database access and subsequent data theft or manipulation. This threatens not only the confidentiality of data but also the integrity and availability of systems run by charitable organizations. An exploited system may experience service disruptions and potential financial and reputational damage. The need for immediate patching and upgrades to secure versions is critical to avert these risks.

REFERENCES

Solution Advice
  • Upgrade to the latest version of WeGIA (3.4.8 or later), which patches this vulnerability.
  • Regularly audit directory access permissions and ensure proper validation of input data.
  • Implement security mechanisms to monitor and log unauthorized access attempts.
  • Consider using web application firewalls to block potential path traversal attack vectors.
  • Conduct periodic security assessments to detect and patch any newly discovered vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.