PT-2025-34256 · Wegia · Wegia

Nilsonlazarin

·

Published

2025-08-21

·

Updated

2025-08-21

·

CVE-2025-57764

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions: WeGIA versions prior to 3.4.7
Description: WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability exists in the cargos.php endpoint of the application. This vulnerability allows attackers to inject malicious scripts through the msg e parameter.
Recommendations: Update to version 3.4.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-57764
GHSA-QX7F-Q867-CGX2

Affected Products

Wegia