Impact
A stored Cross‑Site Scripting vulnerability resides in the Etapas de um Processo page of WeGIA. An authenticated user can insert malicious JavaScript that is persisted and executed when any user, including the injector, accesses the page again, allowing the attacker to hijack sessions and take over accounts.
Affected Systems
The flaw affects all releases of the WeGIA web manager from LabRedesCefetRJ that run before version 3.7.3. The vulnerability was fixed in 3.7.3 and later versions are not impacted.
Risk and Exploitability
With a CVSS score of 6.8 the risk is moderate. No EPSS score is available and the vulnerability is not listed in CISA KEV. Based on the description, the attacker must have valid credentials to inject the malicious payload, indicating that authenticated access is required to exploit the vulnerability. Successful exploitation would enable session hijacking and account compromise.
OpenCVE Enrichment