WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter, which is then directly echoed into the HTML response without any sanitization or encoding. The script /html/memorando/listar_memorandos_ativos.php handles dynamic success messages to users using query string parameters. Similar to other endpoints in the Memorando module, it checks if $_GET['msg'] equals 'success'. If this condition is met, it directly concatenates and reflects $_GET['sccd'] into an HTML alert <div>. This issue is resolved in version 3.6.7.
The script /html/memorando/listar_memorandos_ativos.php handles dynamic success messages for users using query string parameters. When the GET parameter 'msg' has the value 'success', the application directly concatenates and reflects the value of the GET parameter 'sccd' in an HTML alert <div> block, without any sanitization or encoding of input data. An attacker can construct a malicious URL link containing a payload in the 'sccd' parameter and trick the victim into clicking it, resulting in the execution of injected JavaScript code in the context of the user's browser. Due to the Reflected XSS type, the attack requires victim interaction with the prepared link.
An attacker can execute arbitrary JavaScript code in the victim's browser, enabling session theft, credential theft, or sensitive information disclosure displayed on the page, as well as conducting further attacks in the context of a logged-in user. High impact on data confidentiality and integrity (CVSS C:H, I:H) indicates the possibility of user account takeover or data manipulation in the application.
WeGIA should be updated to version 3.6.7, in which the issue has been resolved. The patch is available in the manufacturer's GitHub repository at the address indicated in the references.
WeGIA in versions 3.6.6 and earlier — endpoint /html/memorando/listar_memorandos_ativos.php
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:NWegia
APPWegia< 3.6.7
Related vulnerabilities
Reflected XSS w WeGIA — wstrzyknięcie kodu JS przez parametr GET
SQL Injection w WeGIA — kompromitacja bazy danych przez parametr id_produto
SQL Injection w WeGIA – nieautoryzowane wykonanie poleceń SQL
WeGIA – pominięcie uwierzytelnienia w adicionar_tipo_docs_atendido.php
WeGIA – RCE przez command injection w funkcji przywracania bazy danych