Cross-site scripting in WeGIA - CVE-2025-57764
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting (XSS) in the cargos.php endpoint msg_e parameter when handling a crafted GET request. A remote attacker can send a specially crafted request to execute arbitrary script in the victim's browser.
User interaction is required to load the crafted request in a browser.