Cross-site scripting in WeGIA - #VU127253
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in the pessoa/editar_info_pessoal.php endpoint when handling user-supplied parameters. A remote attacker can send a specially crafted request to execute arbitrary script in a victim's browser.
The issue is reflected and can be triggered through any parameter in the request URL.