CVE-2025-29782: WeGIA Cross-Site Scripting (XSS) Stored in endpoint `adicionar_tipo_docs_atendido.php` parameter `tipo`
WeGIA is Web manager for charitable institutions A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionartipodocsatendido.php endpoint in versions of the WeGIA application prior to 3.2.17. This vulnerability allows attackers to inject malicious scripts into the tipo parameter. The injected scripts are stored on the server and executed automatically whenever the affected page is accessed by users, posing a significant security risk. Version 3.2.17 contains a patch for the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.2.17 - Compensating control
As a temporary mitigation, prevent access to the vulnerable endpoint `adicionar_tipo_docs_atendido.php` (e.g., restrict/limit who can reach it via network controls such as firewall/ACL) until the WeGIA version is upgraded to 3.2.17.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29782?
CVE-2025-29782 is classified as a medium severity vulnerability due to the potential for stored Cross-Site Scripting attacks.
How do I fix CVE-2025-29782?
To fix CVE-2025-29782, upgrade your WeGIA application to version 3.2.17 or later.
What versions of WeGIA are affected by CVE-2025-29782?
CVE-2025-29782 affects all versions of the WeGIA application prior to 3.2.17.
What type of vulnerability is CVE-2025-29782?
CVE-2025-29782 is a Stored Cross-Site Scripting (XSS) vulnerability.
What is the potential impact of CVE-2025-29782?
The potential impact of CVE-2025-29782 includes attackers being able to inject and execute malicious scripts in the web application.