Cross-site scripting in WeGIA - CVE-2025-57765
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to cross-site scripting in the pre_cadastro_adotante.php endpoint when processing the msg_e parameter in a crafted GET request. A remote attacker can inject a malicious script to disclose sensitive information.
User interaction is required to load the crafted request in a browser.