CVE-2025-22140
- EPSS 0.32%
- Veröffentlicht 08.01.2025 19:15:38
- Zuletzt bearbeitet 09.04.2025 18:28:25
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute a...
CVE-2025-22132
- EPSS 0.39%
- Veröffentlicht 07.01.2025 22:15:31
- Zuletzt bearbeitet 13.02.2025 18:55:14
WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malic...
CVE-2025-22133
- EPSS 0.59%
- Veröffentlicht 07.01.2025 22:15:31
- Zuletzt bearbeitet 09.04.2025 18:29:07
WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing ...
CVE-2024-53473
- EPSS 0.18%
- Veröffentlicht 07.12.2024 23:15:34
- Zuletzt bearbeitet 09.04.2025 18:29:29
WeGIA 3.2.0 before 3998672 does not verify permission to change a password.
CVE-2024-53470
- EPSS 0.04%
- Veröffentlicht 05.12.2024 16:15:25
- Zuletzt bearbeitet 09.04.2025 18:30:08
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.
CVE-2024-53471
- EPSS 0.03%
- Veröffentlicht 05.12.2024 16:15:25
- Zuletzt bearbeitet 09.04.2025 18:29:58
Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/meio_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter.
CVE-2024-53472
- EPSS 0.02%
- Veröffentlicht 05.12.2024 16:15:25
- Zuletzt bearbeitet 09.04.2025 18:29:44
WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).