Cross-site scripting in WeGIA - #VU127340

 

Cross-site scripting in WeGIA - #VU127340

Published: April 23, 2026


Vulnerability identifier: #VU127340
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.

The vulnerability exists due to cross-site scripting in html/memorando/listar_memorandos_ativos.php when handling a crafted GET request with the sccd parameter while msg=success. A remote attacker can send a specially crafted URL to execute arbitrary script code in the victim's browser.

User interaction is required, and the victim must open the crafted URL.


Affected software

WeGIA

Remediation

Install security update from vendor's website.

WeGIA - update to 3.6.7

External References

Related Security Bulletins