Cross-site scripting in WeGIA - #VU127352
Published: April 23, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the user's browser.
The vulnerability exists due to cross-site scripting in the Member Registration function when processing the Member Name field and rendering stored input on the contribuições page. A remote attacker can inject a malicious script payload to execute arbitrary script in the user's browser.
The injected payload is persistently stored in the database and is executed when a user navigates to the contribution control page.