CVE-2025-27140

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 24, 2025
Updated: Feb 28, 2025
CWE ID 78
CWE ID 284

Summary

CVE-2025-27140 is a newly disclosed OS Command Injection vulnerability affecting versions prior to 3.2.15 of the WeGIA application. The vulnerable endpoint is `importar_dump.php`. This issue enables attackers to execute arbitrary code remotely by injecting commands through a temporary file movement function. The potential risks include code execution and webshell uploads. WeGIA has released version 3.2.15, which includes a patch for this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share