PT-2025-29863 · Wegia · Wegia

Marcelomulder

·

Published

2025-07-11

·

Updated

2025-07-25

·

CVE-2025-53934

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.5
Description WeGIA is an open-source web manager designed for Portuguese-language use and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability exists in the control.php endpoint. This allows attackers to inject malicious scripts into the descricao emergencia parameter. These scripts are stored on the server and executed when users access the affected page.
Recommendations Update WeGIA to version 3.4.5 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-09269
CVE-2025-53934
GHSA-GQWP-637V-V49V

Affected Products

Wegia