CVE-2025-27420: WeGIA contains a Stored Cross-Site Scripting (XSS) in 'atendido_parentesco_adicionar.php' via the 'descricao' parameter
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the atendidoparentescoadicionar.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the descricao parameter. The injected scripts are stored on the server and executed automatically whenever the affected page is accessed by users, posing a significant security risk. This vulnerability fix in 3.2.16.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27420?
CVE-2025-27420 has been rated as a high severity vulnerability due to its potential for storing malicious scripts.
How do I fix CVE-2025-27420?
To fix CVE-2025-27420, it is recommended to update WeGIA to version 3.2.17 or later, which includes necessary security patches.
What types of attacks can CVE-2025-27420 enable?
CVE-2025-27420 can enable stored cross-site scripting (XSS) attacks, allowing attackers to inject malicious scripts that run in users' browsers.
Which versions of WeGIA are affected by CVE-2025-27420?
WeGIA versions up to 3.2.16 are affected by CVE-2025-27420.
Is user data at risk due to CVE-2025-27420?
Yes, user data is at risk because the stored XSS vulnerability can lead to unauthorized access and exploitation of sensitive information.