PT-2026-3306 · Wegia · Wegia

Marcostolosa

·

Published

2026-01-16

·

Updated

2026-01-17

·

CVE-2026-23722

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.2
Description WeGIA is a Web Manager for Charitable Institutions. A Reflected Cross-Site Scripting (XSS) issue exists within the system, specifically in the html/memorando/insere despacho.php file. The application does not properly sanitize or encode user input provided through the id memorando GET parameter before including it in the HTML output. This allows attackers to inject arbitrary JavaScript or HTML into a user's browser session. The vulnerability allows for unauthorized JavaScript injections and potential session hijacking. The vulnerable parameter is id memorando within the ''insere despacho.php'' file.
Recommendations Versions prior to 3.6.2 should be updated to version 3.6.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-23722
GHSA-G7HH-6QJ7-MCQF

Affected Products

Wegia