Cross-site scripting in WeGIA - #VU127883
Published: April 25, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in the informacao_adicional.php endpoint when processing the descricao parameter. A remote attacker can submit a specially crafted descricao value to execute arbitrary script in a user's browser.
User interaction is required when a victim accesses the affected profile page containing the stored payload.