PT-2026-26607 · Wegia · Wegia
Bao190505
·
Published
2026-03-20
·
Updated
2026-03-22
·
CVE-2026-33136
CVSS v3.1
9.3
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WeGIA versions 3.6.6 and below
Description
WeGIA is a web manager for charitable institutions. The application contains a Reflected Cross-Site Scripting (XSS) issue in the
/html/memorando/listar memorandos ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter. This parameter is then directly echoed into the HTML response without proper sanitization or encoding. The script handles dynamic success messages to users using query string parameters, specifically checking if $ GET['msg'] equals 'success'. If true, it concatenates and reflects $ GET['sccd'] into an HTML alert .
Recommendations
Versions prior to 3.6.7 should be updated to version 3.6.7 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wegia