Cross-site scripting in WeGIA - CVE-2025-53820

 

Cross-site scripting in WeGIA - CVE-2025-53820

Published: April 30, 2026


Vulnerability identifier: #VU128695
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2025-53820
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary script in the victim's browser and disclose sensitive information.

The vulnerability exists due to cross-site scripting (XSS) in the index.php endpoint erro parameter when handling a crafted GET request. A remote attacker can supply a specially crafted erro parameter value to execute arbitrary script in the victim's browser and disclose sensitive information.

User interaction is required to load the crafted request.


Affected software

WeGIA

How to mitigate CVE-2025-53820

Install security update from vendor's website.

WeGIA - update to 3.4.5

External References

Related Security Bulletins