PT-2026-3311 · Wegia · Wegia

Volksec

·

Published

2026-01-16

·

Updated

2026-01-16

·

CVE-2026-23727

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.2
Description WeGIA is a web manager for charitable institutions. An Open Redirect issue exists in the /WeGIA/controle/control.php API endpoint, specifically through the nextPage parameter when used with metodo=listarTodos and nomeClasse=TipoSaidaControle. The application does not properly validate the nextPage parameter, which allows attackers to redirect users to malicious websites. This could be used for phishing attacks, stealing credentials, distributing malware, and social engineering, leveraging the trust associated with the WeGIA domain.
Recommendations Update to version 3.6.2 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-23727
GHSA-PMQ9-8P4W-M4F3

Affected Products

Wegia