Cross-site scripting in WeGIA - #VU136988
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.
The vulnerability exists due to cross-site scripting in listar_despachos.php when rendering stored content from the texto field. A remote user can submit crafted input that is later decoded and injected into the DOM to execute arbitrary JavaScript in the victim's browser and hijack administrator sessions.
The issue is triggered when a victim views the memorandum thread.