Aller au contenu

Fiche vulnérabilité

CVE-2025-53933 : faille moyenne wegia wegia (CVSS 5.4)

Description

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_enfermidade.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `nome` parameter. The injected scripts are stored on the server and executed automatically whenever the affected page is accessed by users, posing a significant security risk. Version 3.4.5 fixes the issue.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
16 juil. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • wegia wegia

Références

Rechercher une autre vulnérabilité dans la base CVE