CVE-2025-22597
CVSS 3.1 Score 8.3 of 10 (high)
Details
Published Jan 10, 2025
CWE ID 79
Summary
CVE-2025-22597 is a stored Cross-Site Scripting (XSS) vulnerability affecting the CobrancaController.php endpoint of the WeGIA application. Attackers can exploit this weakness by injecting malicious scripts into the local_recepcao parameter, which are then stored on the server and executed automatically whenever the affected page is accessed. This poses a significant security risk as unsuspecting users are exposed to potential script execution. The vulnerability is resolved in WeGIA version 3.2.8.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WeGIA