PT-2024-35751 · Wegia · Wegia
Natan Maia Morette
·
Published
2024-12-05
·
Updated
2025-04-09
·
CVE-2024-53471
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WeGIA version 3.2.0
Description
The issue concerns multiple stored cross-site scripting (XSS) vulnerabilities in the /configuracao/meio pagamento.php component. Attackers can execute arbitrary web scripts or HTML via a crafted payload injected into the
id or name parameter. This could potentially lead to account takeover.Recommendations
For WeGIA version 3.2.0, patch immediately and validate all user input to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the /configuracao/meio pagamento.php component until a patch is available. Avoid using the
id or name parameters in the affected component until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia