← volver
CVE-2026-45025

WeGIA: Stored XSS in html/atendido/etapa_processo.php

CVSS 6.8 MEDIUMEPSS 0.2%CWE-79
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the "Etapas de um Processo" (html/atendido/etapa_processo.php) page, which is executed when user access the the page, enabling session hijacking and account takeover. This vulnerability is fixed in 3.7.3.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Productos afectados
LabRedesCefetRJ · WeGIA

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →