CVE-2025-53526
Severity CVSS v4.0:
LOW
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
07/07/2025
Last modified:
10/07/2025
Description
WeGIA is a web manager for charitable institutions. An XSS Injection vulnerability was identified in novo_memorando.php.<br />
After the memo was submitted, the vulnerability was confirmed by accessing listar_memorandos_antigos.php. Upon loading this page, the injected script was executed in the browser. This vulnerability is fixed in 3.4.3.
Impact
Base Score 4.0
2.00
Severity 4.0
LOW
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* | 3.4.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page