Cross-site scripting in WeGIA - CVE-2026-40283

 

Cross-site scripting in WeGIA - CVE-2026-40283

Published: April 23, 2026


Vulnerability identifier: #VU127346
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-40283
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in victims' browsers.

The vulnerability exists due to cross-site scripting in profile_paciente.php when rendering the user-supplied Nome field on the Informações Pacientes page. A remote privileged user can inject malicious HTML or JavaScript into this field to execute arbitrary JavaScript in victims' browsers.

The payload is stored and executed when patient information is viewed.


Affected software

WeGIA

How to mitigate CVE-2026-40283

Install security update from vendor's website.

WeGIA - update to 3.6.10

External References

Related Security Bulletins