Stored Cross-Site Scripting Vulnerability in WeGIA Web Manager
CVE-2025-53929
6.4MEDIUM
What is CVE-2025-53929?
A Stored Cross-Site Scripting (XSS) vulnerability has been found in the WeGIA web manager in the adicionar_cor.php
endpoint. This issue allows attackers to insert malicious scripts into the cor
parameter, which are subsequently stored on the server. The scripts execute automatically when users access the cadastro_pet.php
page, leading to significant security risks. The flaw affects versions prior to 3.4.5, which has implemented a patch to resolve the vulnerability.
Affected Version(s)
WeGIA < 3.4.5