Cross-site scripting in WeGIA - CVE-2025-57762
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting (XSS) in the dependente_docdependente.php endpoint parameter nome when processing crafted POST requests. A remote attacker can submit a specially crafted nome parameter value to execute arbitrary script code in a victim's browser.
User interaction is required when a user accesses the affected page containing the stored payload.