CVE-2025-26613: OS Command Injection endpoint 'gerenciar_backup.php' parameter 'file' (RCE) in WeGIA
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection vulnerability was discovered in the WeGIA application, gerenciarbackup.php endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. This issue has been addressed in version 3.2.14 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIA (gerenciar_backup.php)to a version that resolves this vulnerability.Fixed in 3.2.14
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26613?
CVE-2025-26613 is considered a critical vulnerability due to its potential for remote code execution through OS command injection.
How do I fix CVE-2025-26613?
To remediate CVE-2025-26613, upgrade WeGIA to version 3.2.15 or later, which addresses the OS command injection flaw.
Which versions of WeGIA are affected by CVE-2025-26613?
WeGIA versions up to 3.2.14 are vulnerable to CVE-2025-26613.
What kind of attack can be executed using CVE-2025-26613?
CVE-2025-26613 allows attackers to perform OS command injection, leading to arbitrary code execution on the server.
Is CVE-2025-26613 found in any other software?
CVE-2025-26613 specifically affects the WeGIA application and is not reported in any other software.