GHSA-56r8-9xc4-3g79HighCVSS 6.5
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee...
🔗 CVE IDs covered (1)
📋 Description
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags.
🔗 References (5)
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jqh5-66qr-85qv
- https://nvd.nist.gov/vuln/detail/CVE-2026-76634
- https://github.com/LabRedesCefetRJ/WeGIA/releases#release-3.9.2
- https://www.vulncheck.com/advisories/wegia-insecure-direct-object-reference-via-profile-funcionario-php
- https://github.com/advisories/GHSA-56r8-9xc4-3g79