CVE-2026-35472: WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=EstoqueControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35472?
CVE-2026-35472 has been classified as a medium severity Open Redirect vulnerability.
How do I fix CVE-2026-35472?
To fix CVE-2026-35472, update your WeGIA application to version 3.6.9 or later.
Which versions of WeGIA are affected by CVE-2026-35472?
CVE-2026-35472 affects WeGIA versions prior to 3.6.9.
What is the impact of CVE-2026-35472?
The impact of CVE-2026-35472 allows an attacker to redirect users to malicious sites.
Where is CVE-2026-35472 located in the WeGIA application?
CVE-2026-35472 is located in the /WeGIA/controle/control.php endpoint of the WeGIA application.