CVE-2025-62358
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log parameter in configuracao_geral.php is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can inject arbitrary JavaScript, which executes in the victim’s browser.
This vulnerability is fixed in 3.5.1.
MEDIUM · CVSS 5.4
EPSS 0.00035
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0