Stored Cross-Site Scripting Vulnerability in WeGIA Web Manager
CVE-2025-23031
What is CVE-2025-23031?
A Stored Cross-Site Scripting vulnerability was discovered in the adicionar_alergia.php endpoint of the WeGIA web management application. An attacker can exploit this vulnerability by injecting malicious scripts into the nome parameter, which get stored on the server. When users access the affected page, these scripts are executed in their browsers without proper validation or sanitization of inputs. This can lead to unauthorized access to user data and compromise their systems. Users are recommended to upgrade to version 3.2.6 to mitigate this risk, as no workarounds are available.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
