PT-2026-26606 · Wegia · Wegia

Bao190505

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-33135

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.6.6 and below
Description WeGIA is a web manager for charitable institutions. The software is affected by a Reflected Cross-Site Scripting (XSS) issue in the /novo memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which is directly echoed into the HTML response without sanitization or encoding. The /html/memorando/novo memorandoo.php script reads HTTP GET parameters to display dynamic success messages to the user. Specifically, around line 273, the code checks if $ GET['msg'] equals 'success'. If true, it concatenates $ GET['sccs'] into an HTML alert
and outputs it to the browser.
Recommendations Versions 3.6.6 and below should be updated to version 3.6.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33135
GHSA-W5RV-5884-W94V

Affected Products

Wegia