Unrated severityNVD Advisory· Published Jul 7, 2025· Updated Jul 7, 2025
WeGIA allows Uncontrolled Resource Consumption via the fid parameter
CVE-2025-53531
Description
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the fid parameter. Tests confirmed that the server processes URLs up to 8,142 characters, resulting in high resource consumption, elevated latency, timeouts, and read errors. This makes the server susceptible to Denial of Service (DoS) attacks. This vulnerability is fixed in 3.3.0.
Affected products
1- Range: < 3.3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-4ffc-f23j-54m3mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.