Reflected XSS Vulnerability in WeGIA Web Manager by LabRedesCefetRJ
CVE-2025-53932
6.4MEDIUM
What is CVE-2025-53932?
WeGIA, an open-source web manager designed for Portuguese-speaking charitable institutions, has been identified with a reflected Cross-Site Scripting (XSS) vulnerability in the cadastro_adotante.php
endpoint. This flaw allows an attacker to inject malicious scripts through the cpf
parameter, potentially compromising user data and the integrity of the application. To mitigate this risk, users are advised to upgrade to version 3.4.5 or later, which addresses this vulnerability.
Affected Version(s)
WeGIA < 3.4.5