WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malicious JavaScript code, an attacker can execute arbitrary scripts in the context of a victim's browser. This can lead to information theft, session hijacking, and other forms of client-side exploitation. This vulnerability is fixed in 3.2.7.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WeGIA is a web manager for charitable institutions. A Cross-Site Scripting (XSS) vulnerability was identified in the file upload functionality of the WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. By uploading a file containing malicious JavaScript code, an attacker can execute arbitrary scripts in the context of a victim's browser. This can lead to information theft, session hijacking, and other forms of client-side exploitation. This vulnerability is fixed in 3.2.7. | |
Title | WeGIA has a Cross-Site Scripting (XSS) in File Upload Field | |
Weaknesses | CWE-434 CWE-79 |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-01-07T22:04:41.805Z
Updated: 2025-01-08T15:34:50.893Z
Reserved: 2024-12-30T03:00:33.652Z
Link: CVE-2025-22132
Vulnrichment
Updated: 2025-01-08T15:34:44.118Z
NVD
Status : Received
Published: 2025-01-07T22:15:31.590
Modified: 2025-01-07T22:15:31.590
Link: CVE-2025-22132
Redhat
No data.