PT-2025-29839 · Wegia · Wegia

Nmmorette

+1

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53929

CVSS v4.0
6.4
VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open source web manager. A Stored Cross-Site Scripting (XSS) vulnerability exists in the
adicionar cor.php
endpoint, allowing attackers to inject malicious scripts into the
cor
parameter. These scripts are stored on the server and executed when the
cadastro pet.php
page is accessed by users.
Recommendations Update to version 3.4.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09265
CVE-2025-53929
GHSA-MRWJ-RF3Q-3RQJ

Affected Products

Wegia