Home

Description

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, an Open Redirect vulnerability was identified in the control.php endpoint of the WeGIA application, specifically in the nextPage parameter (metodo=listarTodos nomeClasse=AlmoxarifeControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This vulnerability is fixed in 3.5.0.

PUBLISHED Reserved 2025-10-10 | Published 2025-10-13 | Updated 2025-10-14 | Assigner GitHub_M




MEDIUM: 4.8CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

Problem types

CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

Product status

< 3.5.0
affected

References

github.com/.../WeGIA/security/advisories/GHSA-m99c-77f2-gpjx

github.com/...ommit/2b53003b5956dbbf0ce554b680245f55ad869821

cve.org (CVE-2025-62361)

nvd.nist.gov (CVE-2025-62361)

Download JSON