SB2026070748 - Multiple vulnerabilities in WeGIA
Published: July 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.
The vulnerability exists due to cross-site scripting in listar_despachos.php when rendering stored content from the texto field. A remote user can submit crafted input that is later decoded and injected into the DOM to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.
The issue is triggered when a victim views the memorandum thread.
2) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to access, modify, or delete arbitrary user records.
The vulnerability exists due to improper access control in /controle/control.php and multiple Controle classes when handling POST requests with user-controlled record identifiers via extract($_REQUEST). A remote user can supply crafted id parameters to access, modify, or delete arbitrary user records.
The issue affects multiple CRUD methods across AtendidoControle, InternoControle, FuncionarioControle, and VoluntarioControle.
3) Cross-site request forgery (CVE-ID: N/A)
CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)
CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to perform unauthorized actions via cross-site request forgery.
The vulnerability exists due to cross-site request forgery protection missing in AtendidoControle and InternoControle when handling authenticated requests to /controle/control.php. A remote user can cause a victim's browser to send crafted requests to perform unauthorized actions via cross-site request forgery.
User interaction is required for the victim to visit a malicious page.
4) Cross-site scripting (CVE-ID: N/A)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in saude/historico_prontuarios.php when rendering the textoProntuario field. A remote user can submit a crafted medical record entry to execute arbitrary JavaScript in another user's browser.
User interaction is required when another user views the patient history page.
5) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to create arbitrary billing records.
The vulnerability exists due to missing authorization in cadastro_cobranca.php when handling billing creation requests. A remote attacker can send a specially crafted request to create arbitrary billing records.
6) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify arbitrary member records.
The vulnerability exists due to missing authorization in processa_edicao_socio.php when handling update requests to member records. A remote attacker can send an unauthenticated crafted request to modify arbitrary member records.
7) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to modify payment information.
The vulnerability exists due to missing authorization in atualiza_pagamentos.php when handling payment status update requests. A remote attacker can send a specially crafted request to modify payment information.
The issue can be exploited without authentication to mark arbitrary payment records as paid.
Remediation
Install update from vendor's website.
References
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-83p7-cx5x-7g34
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-rf87-2prr-f2p2
- https://github.com/LabRedesCefetRJ/WeGIA
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-qm7p-cprp-f974
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f732-866c-g3hc
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-pvhq-2cf3-xmch
- https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-c6vj-372g-m3cw