Open redirect in WeGIA - #VU127273
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to redirect users to arbitrary external sites.
The vulnerability exists due to url redirection to untrusted site in /controle/control.php when processing the nextPage parameter. A remote privileged user can craft a trusted-looking link to redirect users to arbitrary external sites.
User interaction is required to follow the crafted link.