CVE-2025-22600
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Jan 10, 2025
CWE ID 79
Summary
CVE-2025-22600 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting the WeGIA web manager for charitable institutions. The issue lies in the configuracao_doacao.php endpoint, where the avulso parameter is susceptible to malicious script injection. Attackers can exploit this weakness to execute malicious code in the context of the affected user. This vulnerability has been addressed in version 3.2.8 of the WeGIA application.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- WeGIA