WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malicious JavaScript code, an attacker can execute arbitrary scripts in the context of a victim's browser. This can lead to information theft, session hijacking, and other forms of client-side exploitation. This vulnerability is fixed in 3.2.7.
History

Wed, 08 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 07 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Description WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malicious JavaScript code, an attacker can execute arbitrary scripts in the context of a victim's browser. This can lead to information theft, session hijacking, and other forms of client-side exploitation. This vulnerability is fixed in 3.2.7.
Title WeGIA has a Cross-Site Scripting (XSS) in File Upload Field
Weaknesses CWE-434
CWE-79
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-07T22:04:41.805Z

Updated: 2025-01-08T15:34:50.893Z

Reserved: 2024-12-30T03:00:33.652Z

Link: CVE-2025-22132

cve-icon Vulnrichment

Updated: 2025-01-08T15:34:44.118Z

cve-icon NVD

Status : Received

Published: 2025-01-07T22:15:31.590

Modified: 2025-01-07T22:15:31.590

Link: CVE-2025-22132

cve-icon Redhat

No data.