CVE-2025-22143

CVSS 3.1 Score 6.1 of 10 (medium)

Details

Published Jan 8, 2025
Updated: Feb 13, 2025
CWE ID 79

Summary

CVE-2025-22143 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the listar_permissoes.php endpoint in the WeGIA web application for charitable institutions. This flaw enables attackers to inject malicious scripts into the msg_e parameter, compromising user sessions and potentially gaining unauthorized access. The vulnerability has been rectified in WeGIA version 3.2.8.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share