← back
CVE-2026-35474

WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']

CVSS 5.1 MEDIUMEPSS 0.2%CWE-601
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Affected products
LabRedesCefetRJ · WeGIA

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →