CVE-2026-40282
Vulnerability Description
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the IntercorrĂȘncias notification page, which is executed when user access the the page, enabling session hijacking and account takeover. Version 3.6.10 fixes the issue.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-79
Source
NVD
Vendor
LabRedesCefetRJ
Product
WeGIA
Discussion (0)
Add Comment
No comments yet. Be the first!