PT-2026-26606 · Wegia · Wegia

Bao190505

·

Publicado

2026-03-20

·

Atualizado

2026-03-22

·

CVE-2026-33135

CVSS v3.1

9.3

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.6.6 and below
Description WeGIA is a web manager for charitable institutions. The software is affected by a Reflected Cross-Site Scripting (XSS) issue in the /novo memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which is directly echoed into the HTML response without sanitization or encoding. The /html/memorando/novo memorandoo.php script reads HTTP GET parameters to display dynamic success messages to the user. Specifically, around line 273, the code checks if $ GET['msg'] equals 'success'. If true, it concatenates $ GET['sccs'] into an HTML alert
and outputs it to the browser.
Recommendations Versions 3.6.6 and below should be updated to version 3.6.7 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33135
GHSA-W5RV-5884-W94V

Produtos afetados

Wegia