CVE-2025-55169 is a path traversal vulnerability in WeGIA, an open-source web manager, affecting versions prior to 3.4.8. This flaw, located in the html/socio/sistema/download_remessa.php endpoint, allows an authenticated attacker to access local server files, including the sensitive config.php which contains database credentials. Rated as Medium severity (CVSS 6.5), the vulnerability has a low attack complexity and requires low privileges, leading to high confidentiality impact. Successful exploitation could grant direct database access. While not actively exploited (no KEV entry), a Nuclei template for this critical vulnerability exists, indicating potential for exploitation. There is currently no public Metasploit module or ExploitDB entry, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.4.8CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.