CVE-2025-22143
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Published Jan 8, 2025
Updated: Feb 13, 2025
CWE ID 79
Summary
CVE-2025-22143 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the listar_permissoes.php endpoint in the WeGIA web application for charitable institutions. This flaw enables attackers to inject malicious scripts into the msg_e parameter, compromising user sessions and potentially gaining unauthorized access. The vulnerability has been rectified in WeGIA version 3.2.8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WeGIA
Affected Vendors
- WE Giá