Clickjacking Vulnerability in WeGIA Web Application
CVE-2026-23731
What is CVE-2026-23731?
The WeGIA web manager for charitable institutions is vulnerable to clickjacking attacks prior to version 3.6.2. This vulnerability arises due to the absence of protective HTTP headers, specifically the missing X-Frame-Options and a poorly configured Content-Security-Policy with the frame-ancestors directive. This allows attackers to manipulate WeGIA pages within malicious HTML documents, potentially overlaying deceptive elements, obscuring legitimate buttons, or coercing users into unintended actions within sensitive workflows. The issue has been addressed in version 3.6.2.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WeGIA < 3.6.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
