CVE-2026-35396: WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IsaidaControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIA applicationto a version that resolves this vulnerability.Fixed in 3.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35396?
The severity of CVE-2026-35396 is moderate due to its potential for exploitation through open redirects.
How do I fix CVE-2026-35396?
To fix CVE-2026-35396, update the WeGIA application to version 3.6.9 or later, which addresses the open redirect vulnerability.
What is the impact of exploiting CVE-2026-35396?
Exploiting CVE-2026-35396 could lead to phishing attacks by redirecting users to malicious sites.
Which versions of WeGIA are affected by CVE-2026-35396?
CVE-2026-35396 affects versions of WeGIA prior to 3.6.9.
What type of vulnerability is CVE-2026-35396?
CVE-2026-35396 is classified as an Open Redirect vulnerability.