Wegia

Wegia

147 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.32%
  • Veröffentlicht 08.01.2025 19:15:38
  • Zuletzt bearbeitet 09.04.2025 18:28:25

WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute a...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 07.01.2025 22:15:31
  • Zuletzt bearbeitet 13.02.2025 18:55:14

WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malic...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 07.01.2025 22:15:31
  • Zuletzt bearbeitet 09.04.2025 18:29:07

WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing ...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 07.12.2024 23:15:34
  • Zuletzt bearbeitet 09.04.2025 18:29:29

WeGIA 3.2.0 before 3998672 does not verify permission to change a password.

Exploit
  • EPSS 0.04%
  • Veröffentlicht 05.12.2024 16:15:25
  • Zuletzt bearbeitet 09.04.2025 18:30:08

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 05.12.2024 16:15:25
  • Zuletzt bearbeitet 09.04.2025 18:29:58

Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.

Exploit
  • EPSS 0.02%
  • Veröffentlicht 05.12.2024 16:15:25
  • Zuletzt bearbeitet 09.04.2025 18:29:44

WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).