WeGIA
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*
- <= 3.6.10
A stored cross-site scripting vulnerability has been identified in WeGIA, a web management tool for charitable organizations, in versions prior to 3.7.0. The issue occurs in the 'Description' field of the 'profile_funcionario.php' endpoint. By injecting a malicious script into this field and saving the profile, the script is persistently stored and executed each time the profile page is accessed.
Exploitation of this vulnerability allows for the injection of malicious scripts that are executed when the profile page is viewed. This could lead to keylogging, credential harvesting, or phishing attacks by manipulating the page to capture sensitive information from the user.
To reproduce this vulnerability, access the 'profile_funcionario.php' endpoint and inject a script into the 'Description' field. Save the profile, and the injected script will be executed whenever the profile page is accessed.
Users can upgrade to WeGIA version 3.7.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.