Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WeGIA is a web manager for charitable institutions. Prior to 3.8.5, web/html/socio/sistema/controller/deletar_socios.php exposes an unauthenticated GET endpoint whose chave parameter is checked only against a hardcoded chave_correta value embedded in the public source repository. A remote attacker who obtains that value can reach the endpoint's TRUNCATE TABLE operations for the endereco, pessoafisica, pessoajuridica, and socio tables without an administrative session or application authorization, permanently destroying member and contributor records. The attack requires the affected tables to exist and the web process database account to possess truncation privileges. This issue is fixed in version 3.8.5. | |
| Title | WeGIA: Hardcoded Secret Key Backdoor — Mass Data Destruction via deletar_socios.php | |
| Weaknesses | CWE-306 CWE-798 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-17T21:56:28.590Z
Reserved: 2026-06-15T23:23:57.713Z
Link: CVE-2026-54767
No data.
Status : Deferred
Published: 2026-09-17T22:17:03.470
Modified: 2026-09-17T22:17:03.597
Link: CVE-2026-54767
No data.
OpenCVE Enrichment
No data.