Cross-site scripting in WeGIA - #VU128704
Published: April 30, 2026
WeGIA
LabReDeS
Description
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the victim's browser.
The vulnerability exists due to cross-site scripting in multiple GET endpoints when reflecting user-supplied URL parameters in HTML responses. A remote attacker can send a specially crafted link to execute arbitrary JavaScript in the victim's browser.
User interaction is required, and the crafted URL must be visited by an authenticated user.