Stored Cross-Site Scripting Vulnerability in WeGIA Web Manager
CVE-2025-23031

5.4MEDIUM

Key Information:

Vendor

WeGIA

Status
Vendor
CVE Published:
14 January 2025

What is CVE-2025-23031?

A Stored Cross-Site Scripting vulnerability was discovered in the adicionar_alergia.php endpoint of the WeGIA web management application. An attacker can exploit this vulnerability by injecting malicious scripts into the nome parameter, which get stored on the server. When users access the affected page, these scripts are executed in their browsers without proper validation or sanitization of inputs. This can lead to unauthorized access to user data and compromise their systems. Users are recommended to upgrade to version 3.2.6 to mitigate this risk, as no workarounds are available.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.