First published: Mon Mar 03 2025(Updated: )
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeGIA. This vulnerability allows any unauthenticated user to cause the server to become unresponsive by performing aggressive spidering. The vulnerability is caused by recursive crawling of dynamically generated URLs and insufficient handling of large volumes of requests. This vulnerability is fixed in 3.2.16.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
WeGIA | <3.2.16 | |
<3.2.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-27419 is classified as medium due to its potential to cause Denial of Service.
To mitigate CVE-2025-27419, upgrade your WeGIA installation to version 3.2.17 or later.
Any instance of WeGIA prior to version 3.2.17 is affected by CVE-2025-27419.
CVE-2025-27419 is a Denial of Service (DoS) vulnerability.
Yes, CVE-2025-27419 can be exploited by any unauthenticated user through aggressive spidering.