CVE-2025-22132
CVSS 3.1 Score 4.8 of 10 (medium)
Details
Published Jan 7, 2025
Updated: Feb 13, 2025
CWE ID 434
CWE ID 79
Summary
CVE-2025-22132 is a Cross-Site Scripting (XSS) vulnerability affecting the file upload functionality of the WeGIA web manager for charitable institutions. By exploiting this weakness in the controla_xlsx.php endpoint, an attacker can upload a malicious file and execute arbitrary JavaScript codes in a victim's browser. The consequences include information theft, session hijacking, and other client-side exploits. This issue has been resolved in version 3.2.7.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WeGIA
Affected Vendors
- WE Giá