Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in WeGIA - CVE-2025-62598
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to improper neutralization of script-related html tags in pessoa/editar_info_pessoal.php when handling a crafted action parameter in a GET request. A remote attacker can send a specially crafted request to execute arbitrary script in the victim's browser.