PT-2026-26607 · Wegia · Wegia

Bao190505

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-33136

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions 3.6.6 and below
Description WeGIA is a web manager for charitable institutions. The application contains a Reflected Cross-Site Scripting (XSS) issue in the /html/memorando/listar memorandos ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter. This parameter is then directly echoed into the HTML response without proper sanitization or encoding. The script handles dynamic success messages to users using query string parameters, specifically checking if $ GET['msg'] equals 'success'. If true, it concatenates and reflects $ GET['sccd'] into an HTML alert
.
Recommendations Versions prior to 3.6.7 should be updated to version 3.6.7 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-33136
GHSA-XJQP-5Q3H-2CXH

Affected Products

Wegia