Cross-site scripting in WeGIA - CVE-2025-30363
Published: March 27, 2025 / Updated: April 30, 2026
WeGIA
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.
The vulnerability exists due to cross-site scripting in the dados_addInfo parameter of html/geral/documentos_funcionario.php when processing user-supplied input. A remote attacker can submit a specially crafted payload to execute arbitrary script code in the victim's browser.
User interaction is required when a user accesses the affected page, including funcionario/profile_funcionario.php.