PT-2025-41822 · Wegia · Wegia

Marcelomulder

·

Published

2025-10-13

·

Updated

2025-10-20

·

CVE-2025-62361

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.5.0
Description WeGIA is a Web Manager for Institutions focused on Portuguese language users. A flaw exists that allows redirection to arbitrary external domains via the nextPage parameter in the ''control.php'' endpoint (metodo=listarTodos nomeClasse=AlmoxarifeControle). This can be used for phishing, distributing malicious payloads, or stealing user credentials.
Recommendations Update to version 3.5.0 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-62361
GHSA-M99C-77F2-GPJX

Affected Products

Wegia