Reflected XSS Vulnerability in WeGIA Web Manager for Institutions
CVE-2025-62178
3.5LOW
What is CVE-2025-62178?
The WeGIA application, an open-source Web Manager for Institutions, was found to have a reflected Cross-Site Scripting (XSS) vulnerability in the /html/atendido/cadastro_atendido_parentesco_pessoa_nova.php endpoint prior to version 3.5.1. By exploiting this flaw, attackers could inject malicious scripts through the idatendido parameter, potentially compromising user data and application integrity. The vulnerability has been addressed in version 3.5.1, which users are encouraged to upgrade to in order to mitigate security risks.
Affected Version(s)
WeGIA < 3.5.1