CVE 6.4 MEDIUM

WeGIA: Cross-Site Scripting (XSS) Stored endpoint ‘informacao_adicional.php’ parameter ‘descricao’_CVE-2026-42870

6.4 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:H/SI:H/SA:H

Description

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the following endpoint: funcionario/profile_funcionario.php?id_funcionario=2. By injecting a malicious payload into the 'Description' (Descrição) field and saving the profile, the script becomes persistently stored. The payload is subsequently executed whenever the profile page is accessed. This vulnerability is fixed in 3.7.0.

Basic Information

ID CVE-2026-42870
Source GitHub_M
Published May 11, 2026 at 18:32

Affected Product

Vendor LabRedesCefetRJ
Product WeGIA
Version < 3.7.0
Affected Versions LabRedesCefetRJ WeGIA < 3.7.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.