Cross-site scripting in WeGIA - CVE-2025-53933
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting (XSS) in the adicionar_enfermidade.php endpoint parameter nome when processing a crafted POST request to /html/saude/adicionar_enfermidade.php. A remote attacker can submit a specially crafted nome parameter value to execute arbitrary script code in a victim's browser.
User interaction is required when a user accesses the affected page containing the stored payload.