Stored Cross-Site Scripting Vulnerability in WeGIA by LabRedesCefetRJ
CVE-2026-45025

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-45025?

The WeGIA web manager for charitable institutions is susceptible to a Stored Cross-Site Scripting vulnerability that affects versions earlier than 3.7.3. An authenticated user can exploit this flaw by injecting malicious JavaScript into the 'Etapas de um Processo' page. When accessed, the injected script is executed, potentially leading to session hijacking and unauthorized account access. To mitigate the risk, it is crucial to update to version 3.7.3 or later.

Affected Version(s)

WeGIA < 3.7.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.