CVE-2025-53531
WeGIA allows Uncontrolled Resource Consumption via the fid parameter
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the fid parameter. Tests confirmed that the server processes URLs up to 8,142 characters, resulting in high resource consumption, elevated latency, timeouts, and read errors. This makes the server susceptible to Denial of Service (DoS) attacks. This vulnerability is fixed in 3.3.0.
WeGIA es un gestor web para instituciones benéficas. El servidor Wegia presenta una vulnerabilidad que permite solicitudes HTTP GET excesivamente largas a una URL específica. Este problema se debe a la falta de validación de la longitud del parámetro fid. Las pruebas confirmaron que el servidor procesa URL de hasta 8142 caracteres, lo que resulta en un alto consumo de recursos, alta latencia, tiempos de espera y errores de lectura. Esto hace que el servidor sea susceptible a ataques de denegación de servicio (DoS). Esta vulnerabilidad se corrigió en la versión 3.3.0.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-07-02 CVE Reserved
- 2025-07-07 CVE Published
- 2025-07-07 CVE Updated
- 2025-07-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-770: Allocation of Resources Without Limits or Throttling
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-4ffc-f23j-54m3 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
LabRedesCefetRJ Search vendor "LabRedesCefetRJ" | WeGIA Search vendor "LabRedesCefetRJ" for product "WeGIA" | < 3.3.0 Search vendor "LabRedesCefetRJ" for product "WeGIA" and version " < 3.3.0" | en |
Affected
|