PT-2026-26607 · Wegia · Wegia

Bao190505

·

Publicado

2026-03-20

·

Atualizado

2026-03-22

·

CVE-2026-33136

CVSS v3.1

9.3

Crítica

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.6.6 and below
Description WeGIA is a web manager for charitable institutions. The application contains a Reflected Cross-Site Scripting (XSS) issue in the /html/memorando/listar memorandos ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter. This parameter is then directly echoed into the HTML response without proper sanitization or encoding. The script handles dynamic success messages to users using query string parameters, specifically checking if $ GET['msg'] equals 'success'. If true, it concatenates and reflects $ GET['sccd'] into an HTML alert
.
Recommendations Versions prior to 3.6.7 should be updated to version 3.6.7 or later.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33136
GHSA-XJQP-5Q3H-2CXH

Produtos afetados

Wegia