PT-2025-29862 · Wegia · Wegia

Marcelomulder

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53933

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open source web manager. A Stored Cross-Site Scripting (XSS) vulnerability exists in the adicionar enfermidade.php endpoint. This allows attackers to inject malicious scripts into the nome parameter, which are then stored on the server and executed when users access the affected page.
Recommendations Update WeGIA to version 3.4.5 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09268
CVE-2025-53933
GHSA-6558-M8RP-5QG6

Affected Products

Wegia