CVE-2024-53473: Broken Access Control
CVE Publication: https://www.cve.org/CVERecord?id=CVE-2024-53473
Vendor
WeGIA (Web Gerenciador Institucional) is an integrated management system licensed under the GNU GPL v3.0, designed to enhance administration, control, and transparency for institutions.
https://sol.sbc.org.br/index.php/latinoware/article/view/31544
Affected Product Code Base
WeGIA < v3.2.0
Vulnerability Description
A critical vulnerability was identified in the web application WeGIa. This vulnerability allows an attacker to change the password of the admin user by sending a POST request to the control.php
endpoint without requiring authentication or authorization.
POC
Burp Request:
Curl Request:
|
|
References
https://github.com/nilsonLazarin/WeGIA/issues/791
https://github.com/LabRedesCefetRJ/WeGIA/
Discoverer
By: CVE-Hunters