CVE-2025-22599

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 10, 2025
CWE ID 79

Summary

CVE-2025-22599 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the home.php endpoint of the WeGIA web management application for charitable institutions. This issue allows attackers to inject malicious scripts into the msg_c parameter, potentially executing arbitrary code in the context of the affected user. Successful exploitation could lead to unauthorized access, data theft, or website defacement. Users are advised to upgrade to version 3.2.8 to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share