CVE-2026-35398: WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos & listarIdNome and nomeClasse=OrigemControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35398?
CVE-2026-35398 has been classified as a medium severity Open Redirect vulnerability.
How do I fix CVE-2026-35398?
To fix CVE-2026-35398, upgrade WeGIA to version 3.6.9 or later.
What component is affected by CVE-2026-35398?
The affected component in CVE-2026-35398 is the /WeGIA/controle/control.php endpoint.
What are the implications of CVE-2026-35398?
CVE-2026-35398 allows an attacker to redirect users to malicious websites through the unvalidated 'nextPage' parameter.
Which software versions are impacted by CVE-2026-35398?
Versions of WeGIA prior to 3.6.9 are impacted by CVE-2026-35398.