Stored Cross-Site Scripting Vulnerability in WeGIA by LabRedesCefetRJ
CVE-2026-45025
6.8MEDIUM
What is CVE-2026-45025?
The WeGIA web manager for charitable institutions is susceptible to a Stored Cross-Site Scripting vulnerability that affects versions earlier than 3.7.3. An authenticated user can exploit this flaw by injecting malicious JavaScript into the 'Etapas de um Processo' page. When accessed, the injected script is executed, potentially leading to session hijacking and unauthorized account access. To mitigate the risk, it is crucial to update to version 3.7.3 or later.
Affected Version(s)
WeGIA < 3.7.3
