Stored Cross-Site Scripting Vulnerability in WeGIA Web Manager
CVE-2026-40284
6.8MEDIUM
What is CVE-2026-40284?
The WeGIA web manager for charitable institutions contains a vulnerability that allows authenticated users to inject malicious JavaScript into the 'Destinatário' field. This payload is stored in the system and executed whenever another user accesses the dispatch page, potentially compromising user data and security. The issue has been addressed in version 3.6.10.
Affected Version(s)
WeGIA < 3.6.10
