Stored Cross-Site Scripting Vulnerability in WeGIA Web Manager by LabRedesCefetRJ
CVE-2025-53933
6.4MEDIUM
What is CVE-2025-53933?
The WeGIA open-source web management application, specifically designed for Portuguese-speaking charitable organizations, has a vulnerability located in the adicionar_enfermidade.php
endpoint. This Stored Cross-Site Scripting (XSS) flaw allows attackers to leverage the nome
parameter, injecting malicious scripts that are stored on the server. When users access the affected page, these scripts execute automatically, leading to severe implications for data integrity and user trust. Users are urged to update to version 3.4.5 to mitigate the risk associated with this vulnerability.
Affected Version(s)
WeGIA < 3.4.5