CVE-2025-27419: Denial of Service (DoS) in WeGIA due to Recursive Crawling of Dynamic URLs
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeGIA. This vulnerability allows any unauthenticated user to cause the server to become unresponsive by performing aggressive spidering. The vulnerability is caused by recursive crawling of dynamically generated URLs and insufficient handling of large volumes of requests. This vulnerability is fixed in 3.2.16.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27419?
The severity of CVE-2025-27419 is classified as medium due to its potential to cause Denial of Service.
How do I fix CVE-2025-27419?
To mitigate CVE-2025-27419, upgrade your WeGIA installation to version 3.2.17 or later.
Who is affected by CVE-2025-27419?
Any instance of WeGIA prior to version 3.2.17 is affected by CVE-2025-27419.
What type of vulnerability is CVE-2025-27419?
CVE-2025-27419 is a Denial of Service (DoS) vulnerability.
Can unauthenticated users exploit CVE-2025-27419?
Yes, CVE-2025-27419 can be exploited by any unauthenticated user through aggressive spidering.