Cross-site scripting in WeGIA - #VU136988

 

Cross-site scripting in WeGIA - #VU136988

Published: July 7, 2026


Vulnerability identifier: #VU136988
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.

The vulnerability exists due to cross-site scripting in listar_despachos.php when rendering stored content from the texto field. A remote user can submit crafted input that is later decoded and injected into the DOM to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.

The issue is triggered when a victim views the memorandum thread.


Affected software

WeGIA

Remediation

Install security update from vendor's website.

WeGIA - update to 3.8.7

External References

Related Security Bulletins