PT-2025-30058 · Wegia · Wegia

Whyrusx

·

Published

2025-07-17

·

Updated

2025-07-18

·

CVE-2025-54078

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.4.6
Description WeGIA is an open source web manager designed for the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability exists that allows attackers to inject malicious scripts via the err parameter in the personalizacao imagem.php endpoint.
Recommendations Update to version 3.4.6 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-09407
CVE-2025-54078
GHSA-F4J2-MXWH-RFM7

Affected Products

Wegia