CVE-2025-22597

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Jan 10, 2025
CWE ID 79

Summary

CVE-2025-22597 is a stored Cross-Site Scripting (XSS) vulnerability affecting the CobrancaController.php endpoint of the WeGIA application. Attackers can exploit this weakness by injecting malicious scripts into the local_recepcao parameter, which are then stored on the server and executed automatically whenever the affected page is accessed. This poses a significant security risk as unsuspecting users are exposed to potential script execution. The vulnerability is resolved in WeGIA version 3.2.8.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share