CVE-2026-23722 : Détail

CVE-2026-23722

9.1
/
Critique
Cross-site Scripting
A03-Injection
0.07%V4
Network
2026-01-16
19h29 +00:00
2026-01-16
21h35 +00:00
Notifications pour un CVE
Restez informé de toutes modifications pour un CVE spécifique.
Gestion des notifications

Descriptions du CVE

WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrary code execution and UI redressing.

WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via the id_memorando GET parameter before reflecting it into the HTML source (likely inside a

Products Mentioned

Configuraton 0

Wegia>>Wegia >> Version To (excluding) 3.6.2

Références