CVE-2025-27140: WeGIA vulnerable to OS Command Injection at endpoint 'importar_dump.php' parameter 'import' (RCE)
WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, importardump.php endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.15 - Compensating control
If you cannot immediately upgrade, restrict access to the importar_dump.php endpoint (import parameter) to trusted users/IPs using network controls (e.g., firewall/ACL) to reduce exposure to remote command injection.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27140?
CVE-2025-27140 is considered a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-27140?
To mitigate CVE-2025-27140, upgrade to WeGIA version 3.2.15 or later.
What versions are affected by CVE-2025-27140?
CVE-2025-27140 affects all versions of WeGIA prior to 3.2.15.
What type of vulnerability is CVE-2025-27140?
CVE-2025-27140 is classified as an OS Command Injection vulnerability.
What could an attacker achieve with CVE-2025-27140?
An attacker exploiting CVE-2025-27140 could execute arbitrary code on the server remotely.