CVE-2025-67496 - WeGia is Vulnerable to XSS through id_pessoa Parameter on Password Configuration...

CVE-2025-67496 - WeGia is Vulnerable to XSS through id_pessoa Parameter on Password Configuration...

CVE ID : CVE-2025-67496 Published : Dec. 9, 2025, 11:16 p.m. | 1 hour, 18 minutes ago Description : WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. The application retrieves employee names from the database and injects them directly into HTML elements without proper escaping. This issue is fixed in version 3.5.5. Severity: 4.3 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 9, 2025
Affected Product: php
Impact: XSS

Source: Telegram CVE Monitor