Impact
The vulnerability allows an attacker to embed any page of the WeGIA web manager within a malicious iframe because the application fails to send framing protection headers. This omission enables clickjacking, allowing attackers to overlay deceptive content, conceal real controls, or trick users into interacting with hidden elements that trigger sensitive workflows. As a result, unauthorized or accidental actions can be performed without the user’s knowledge, potentially exposing confidential data or altering system state.
Affected Systems
LabRedesCefetRJ’s WeGIA web manager is affected. Versions prior to 3.6.2 are vulnerable.
Risk and Exploitability
The CVSS score is 4.3, indicating a low to moderate risk. The EPSS score is below 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited exploitation activity. Attackers can exploit the flaw via a web‑based attack that hosts a malicious page containing an iframe to a vulnerable WeGIA page; no authentication or special privileges are required beyond user interaction. The risk therefore mainly stems from social engineering and UI deception rather than direct code execution.
OpenCVE Enrichment