Cross-site scripting in WeGIA - CVE-2025-53934
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting (stored XSS) in the control.php endpoint parameter descricao_emergencia when processing a crafted POST request to /controle/control.php. A remote attacker can submit a specially crafted descricao_emergencia value to execute arbitrary script in a victim's browser.
User interaction is required when a user accesses the affected page containing the stored payload.