Reflected Cross-Site Scripting Vulnerability in WeGIA Web Manager by LabRedes
CVE-2026-23722
9.1CRITICAL
What is CVE-2026-23722?
A reflected cross-site scripting (XSS) vulnerability exists in the WeGIA Web Manager for Charitable Institutions prior to version 3.6.2. The flaw arises from inadequate sanitization or encoding of user-supplied input via the id_memorando GET parameter. As a result, this allows attackers to inject arbitrary JavaScript or HTML, potentially compromising an authenticated user's browser session. Affected users are strongly encouraged to upgrade to version 3.6.2 or later to mitigate the risk.
Affected Version(s)
WeGIA < 3.6.2
