CVE-2026-23722 : Detail

CVE-2026-23722

9.1
/
Critical
Cross-site Scripting
A03-Injection
0.07%V4
Network
2026-01-16
19h29 +00:00
2026-01-16
21h35 +00:00
Notifications for a CVE
Stay informed of any changes for a specific CVE.
Notifications manage

CVE Descriptions

WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrary code execution and UI redressing.

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via the id_memorando GET parameter before reflecting it into the HTML source (likely inside a

Products Mentioned

Configuraton 0

Wegia>>Wegia >> Version To (excluding) 3.6.2

References