CVE-2024-57032: Wegia
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
Affected products
- Wegia Wegia: before 3.2.0 (fixed in 3.2.0)
Published 2025-01-17. Last modified 2026-06-17.