Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in WeGIA - CVE-2025-62597
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of script-related html tags in pessoa/editar_info_pessoal.php when handling a crafted GET request parameter. A remote attacker can supply a specially crafted parameter value to execute arbitrary script in the victim's browser.