Junglewise Threat Intelligence

CVE-2026-35473: LabRedesCefetRJ WeGIA open redirect in control.php

CVE-2026-35473 · Severity: medium · CVSS 6.1 · Published 2026-04-06

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA is a web-based management platform used by charitable organizations to coordinate their operations. A security flaw allows attackers to create malicious links that appear to be from the trusted WeGIA domain but redirect users to external, harmful websites. This can be used to trick staff or administrators into visiting phishing pages to steal their login credentials or download malware.

Technical details

An open redirect vulnerability exists in WeGIA versions prior to 3.6.9 due to insufficient validation of the 'nextPage' parameter in the /WeGIA/controle/control.php endpoint. The flaw is specifically exploitable when the 'metodo' parameter is set to 'listarId' and 'nomeClasse' is set to 'IentradaControle'. An unauthenticated remote attacker can craft a URL that, when clicked by a user, redirects them to an arbitrary external domain. This vulnerability can be leveraged for phishing or social engineering attacks. The issue has been resolved in version 3.6.9.

Affected products

  • LabRedesCefetRJ WeGIA < 3.6.9

Timeline

  • 2026-04-02: advisory: GitHub security advisory published by vendor
  • 2026-04-06: disclosed: CVE published to NVD
  • 2026-04-06: patched: Vulnerability fixed in version 3.6.9

References

Related threats