Cross-site scripting in WeGIA - #VU136991

 

Cross-site scripting in WeGIA - #VU136991

Published: July 7, 2026


Vulnerability identifier: #VU136991
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser.

The vulnerability exists due to cross-site scripting in saude/historico_prontuarios.php when rendering the textoProntuario field. A remote user can submit a crafted medical record entry to execute arbitrary JavaScript in another user's browser.

User interaction is required when another user views the patient history page.


Affected software

WeGIA

Remediation

Install security update from vendor's website.

WeGIA - update to 3.8.7

External References

Related Security Bulletins