First published: Wed Jan 08 2025(Updated: )
WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_geral.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wegia Wegia | <3.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-22139 is classified as a medium severity Reflected Cross-Site Scripting (XSS) vulnerability.
To fix CVE-2025-22139, ensure proper validation and encoding of the msg_c parameter in the configuracao_geral.php endpoint.
CVE-2025-22139 affects WeGIA versions up to, but not including, 3.2.8.
Yes, CVE-2025-22139 can be exploited remotely through crafted HTTP requests that include malicious scripts.
Exploitation of CVE-2025-22139 may allow attackers to execute arbitrary scripts in the context of a user's browser.