Cross-site scripting in WeGIA - #VU136991
Published: July 7, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.
The vulnerability exists due to cross-site scripting in saude/historico_prontuarios.php when rendering the textoProntuario field. A remote user can submit a crafted medical record entry to execute arbitrary JavaScript in another user's browser.
User interaction is required when another user views the patient history page.