Stored Cross-Site Scripting Vulnerability in WeGIA by LabRedesCefetRJ
CVE-2025-22613
What is CVE-2025-22613?
WeGIA, an open source web management application targeting Portuguese-speaking charitable institutions, is vulnerable to Stored Cross-Site Scripting (XSS). The flaw exists in the informacao_adicional.php endpoint where user input is not properly validated or sanitized. This allows attackers to inject malicious scripts through the descricao parameter, which are then stored on the server. When the affected page is accessed, these scripts execute in the browsers of users, potentially leading to data theft and system compromise. Users are strongly advised to update to version 3.2.6 to mitigate this security risk, as there are no known workarounds.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.2.6
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
