CVE-2025-53526

WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php. After the memo was submitted, the vulnerability was confirmed by accessing listar_memorandos_antigos.php. Upon loading this page, the injected script was executed in the browser. This vulnerability is fixed in 3.4.3.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

History

10 Jul 2025, 21:17

Type Values Removed Values Added
CPE cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.1
First Time Wegia
Wegia wegia
References () https://github.com/LabRedesCefetRJ/WeGIA/commit/f8cf5d0473334e6c28ea7f604da11ee2a7b419df - () https://github.com/LabRedesCefetRJ/WeGIA/commit/f8cf5d0473334e6c28ea7f604da11ee2a7b419df - Patch
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-46fm-hx2r-69fg - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-46fm-hx2r-69fg - Exploit, Vendor Advisory

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) WeGIA es un gestor web para instituciones benéficas. Se identificó una vulnerabilidad de inyección XSS en novo_memorando.php. Tras enviar el memorando, se confirmó la vulnerabilidad accediendo a listar_memorandos_antigos.php. Al cargar esta página, el script inyectado se ejecutó en el navegador. Esta vulnerabilidad está corregida en la versión 3.4.3.

07 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-07 17:15

Updated : 2025-07-10 21:17


NVD link : CVE-2025-53526

Mitre link : CVE-2025-53526

CVE.ORG link : CVE-2025-53526


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')