Executive brief
WeGIA is a web-based management platform used by charitable organizations to coordinate their operations. A security flaw allows attackers to create malicious links that appear to be from the trusted WeGIA domain but redirect users to external, harmful websites. This can be used to trick staff or administrators into visiting phishing pages to steal their login credentials or download malware.
Technical details
An open redirect vulnerability exists in WeGIA versions prior to 3.6.9 due to insufficient validation of the 'nextPage' parameter in the /WeGIA/controle/control.php endpoint. The flaw is specifically exploitable when the 'metodo' parameter is set to 'listarId' and 'nomeClasse' is set to 'IentradaControle'. An unauthenticated remote attacker can craft a URL that, when clicked by a user, redirects them to an arbitrary external domain. This vulnerability can be leveraged for phishing or social engineering attacks. The issue has been resolved in version 3.6.9.
Affected products
- LabRedesCefetRJ WeGIA < 3.6.9
Timeline
- 2026-04-02: advisory: GitHub security advisory published by vendor
- 2026-04-06: disclosed: CVE published to NVD
- 2026-04-06: patched: Vulnerability fixed in version 3.6.9