PT-2025-5264 · Wegia · Wegia

Rafaelcorvino1

·

Published

2025-01-21

·

Updated

2025-02-13

·

CVE-2025-24020

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions up to and including 3.2.10
Description WeGIA is a Web manager for charitable institutions. An Open Redirect issue was identified in the control.php endpoint, allowing the nextPage parameter to be manipulated and redirecting authenticated users to arbitrary external URLs without validation. This issue stems from the lack of validation for the nextPage parameter, which accepts external URLs as redirection destinations. The issue can be exploited to perform phishing attacks or redirect users to malicious websites.
Recommendations For versions up to and including 3.2.10, update to version 3.2.11 to resolve the issue. As a temporary workaround, consider restricting access to the control.php endpoint or validating the nextPage parameter to minimize the risk of exploitation.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-24020
GHSA-27G8-5Q48-XMW6

Affected Products

Wegia