Open Redirect Vulnerability in WeGIA Web Manager for Charitable Institutions
CVE-2026-23729
4.8MEDIUM
What is CVE-2026-23729?
An Open Redirect vulnerability exists in the WeGIA web manager application, particularly in the /WeGIA/controle/control.php endpoint. Attackers can exploit this flaw by manipulating the nextPage parameter, which is not properly validated. This oversight allows for malicious redirects, enabling attackers to direct users to arbitrary external sites. Consequently, this vulnerability poses risks of phishing scams, credential theft, and the potential distribution of malware. The issue was addressed in version 3.6.2 of the application, emphasizing the importance of updating to safeguard against these attacks.
Affected Version(s)
WeGIA < 3.6.2
