CVE-2026-35474: WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, open redirect has been found in WeGIA webapp. The redirect parameter is taken directly from $GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WeGIAto a version that resolves this vulnerability.Fixed in 3.6.9
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35474?
CVE-2026-35474 is classified as a high severity vulnerability due to its potential for exploitation through open redirects.
How do I fix CVE-2026-35474?
To fix CVE-2026-35474, update to version 3.6.9 or later of WeGIA that includes URL validation for the redirect parameter.
What kind of vulnerability is CVE-2026-35474?
CVE-2026-35474 is an open redirect vulnerability that allows attackers to redirect users to untrusted sites.
Who is affected by CVE-2026-35474?
CVE-2026-35474 affects all versions of WeGIA prior to version 3.6.9.
What are the risks associated with CVE-2026-35474?
The risks associated with CVE-2026-35474 include phishing attacks and bypassing security measures through malicious redirects.