Cross-site scripting in WeGIA - CVE-2025-30366
Published: March 27, 2025 / Updated: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in a user's browser.
The vulnerability exists due to cross-site scripting in personalizacao.php when processing input in the titulo, subtitulo, conheça, objetivo, and rodape parameters. A remote privileged user can submit specially crafted input to execute arbitrary script in a user's browser.
User interaction is required when a victim accesses the home page or personalizacao.php.