PT-2025-5264 · Wegia · Wegia
Rafaelcorvino1
·
Published
2025-01-21
·
Updated
2025-02-13
·
CVE-2025-24020
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WeGIA versions up to and including 3.2.10
Description
WeGIA is a Web manager for charitable institutions. An Open Redirect issue was identified in the
control.php endpoint, allowing the nextPage parameter to be manipulated and redirecting authenticated users to arbitrary external URLs without validation. This issue stems from the lack of validation for the nextPage parameter, which accepts external URLs as redirection destinations. The issue can be exploited to perform phishing attacks or redirect users to malicious websites.Recommendations
For versions up to and including 3.2.10, update to version 3.2.11 to resolve the issue.
As a temporary workaround, consider restricting access to the
control.php endpoint or validating the nextPage parameter to minimize the risk of exploitation.Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia