Cross-site scripting in WeGIA - CVE-2025-53526
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in novo_memorando.php when processing memo content that is later rendered in listar_memorandos_antigos.php. A remote attacker can submit a specially crafted memo to execute arbitrary script in a victim's browser.
User interaction is required when a user loads the old memo listing page.