WeGIA
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*
- < 3.2.0
A stored cross-site scripting (XSS) vulnerability exists in WeGIA versions prior to 3.2.0. The issue is located in the 'documentos_funcionario.php' file, specifically within the 'id' parameter. This vulnerability allows unauthorized scripts to be executed in the user's browser, with the malicious code being permanently stored on the server and executed whenever the compromised page is accessed.
Exploitation of this vulnerability allows for stored cross-site scripting, where injected scripts are executed in the context of the user viewing the affected page.
To reproduce this vulnerability, insert a script payload into the 'id' parameter of the 'documentos_funcionario.php' file and save the changes. The injected script will be executed for any user accessing the 'html/geral/documentos_funcionario.php' page, confirming the presence of stored XSS.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.