PT-2025-32895 · Wegia · Wegia

Ducluongtran9121

+1

·

Published

2025-08-12

·

Updated

2025-08-13

·

CVE-2025-55170

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.8
Description: WeGIA is a web manager with a focus on the Portuguese language and charitable institutions. A reflected cross-site scripting (XSS) vulnerability exists in the /html/alterar senha.php API endpoint. Attackers can inject malicious scripts through the verificacao and redir config parameters.
Recommendations: Update to version 3.4.8 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-55170
GHSA-77HC-C8F4-P3HC

Affected Products

Wegia