CVE-2025-22132

WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malicious JavaScript code, an attacker can execute arbitrary scripts in the context of a victim's browser. This can lead to information theft, session hijacking, and other forms of client-side exploitation. This vulnerability is fixed in 3.2.7.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

History

13 Feb 2025, 18:55

Type Values Removed Values Added
Summary
  • (es) WeGIA es un gestor web para instituciones benéficas. Se ha identificado una vulnerabilidad de tipo Cross-Site Scripting (XSS) en la funcionalidad de carga de archivos del endpoint WeGIA/html/socio/sistema/controller/controla_xlsx.php. Al cargar un archivo que contiene código JavaScript malicioso, un atacante puede ejecutar secuencias de comandos arbitrarias en el contexto del navegador de la víctima. Esto puede provocar robo de información, secuestro de sesiones y otras formas de explotación del lado del cliente. Esta vulnerabilidad se ha corregido en la versión 3.2.7.
References () https://github.com/nilsonLazarin/WeGIA/commit/330f641db43cfb0c8ea8bb6025cc0732de4d4d6b - () https://github.com/nilsonLazarin/WeGIA/commit/330f641db43cfb0c8ea8bb6025cc0732de4d4d6b - Patch
References () https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-h8hr-jhcx-fcv9 - () https://github.com/nilsonLazarin/WeGIA/security/advisories/GHSA-h8hr-jhcx-fcv9 - Exploit, Vendor Advisory
First Time Wegia
Wegia wegia
CPE cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

07 Jan 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-07 22:15

Updated : 2025-02-13 18:55


NVD link : CVE-2025-22132

Mitre link : CVE-2025-22132

CVE.ORG link : CVE-2025-22132


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-434

Unrestricted Upload of File with Dangerous Type