PT-2025-28216 · Wegia · Wegia
Pedro-Lyrio
·
Published
2025-07-07
·
Updated
2025-07-07
·
CVE-2025-53526
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
WeGIA versions prior to 3.4.3
Description:
A Cross-Site Scripting (XSS) Injection issue was found in WeGIA, a web manager for charitable institutions. The vulnerability is located in the
novo memorando.php file. When a memo is submitted, the injected script is executed in the browser upon loading the listar memorandos antigos.php page.Recommendations:
For versions prior to 3.4.3, update to version 3.4.3 to resolve the issue. As a temporary workaround, consider restricting access to the
novo memorando.php and listar memorandos antigos.php pages until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia