PT-2025-34249 · Wegia · Wegia

Marcelomulder

·

Published

2025-08-21

·

Updated

2025-08-22

·

CVE-2025-57762

CVSS v4.0

6.4

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.7
Description: WeGIA is a Web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability exists in the dependente docdependente.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the nome parameter. The injected scripts are stored on the server and executed automatically when users access the affected page.
Recommendations: Update WeGIA to version 3.4.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57762
GHSA-494R-43F3-P828

Affected Products

Wegia