Junglewise Threat Intelligence

CVE-2026-42872: LabRedesCefetRJ WeGIA reflected XSS in lista_arquivos_etapa.php

CVE-2026-42872 · Severity: medium · CVSS 6.1 · Published 2026-05-11

Technologies: LabRedesCefetRJ WeGIA. Vendors: LabRedesCefetRJ.

Executive brief

WeGIA, a web-based management platform for charitable institutions, is vulnerable to a security flaw that allows attackers to run malicious scripts in a user's browser. By tricking a staff member or administrator into clicking a specially crafted link, an attacker could steal login sessions, capture sensitive credentials, or perform unauthorized actions on behalf of the user. This could compromise the management of institutional data and donor information.

Technical details

A reflected Cross-Site Scripting (XSS) vulnerability exists in WeGIA versions prior to 3.7.0 within the 'lista_arquivos_etapa.php' component. The root cause is the improper neutralization of the 'id_processo' GET parameter, which is directly echoed into a hidden HTML input field without sanitization or encoding. An unauthenticated remote attacker can exploit this by inducing a victim to visit a crafted URL containing malicious JavaScript. Successful exploitation allows for the execution of arbitrary code in the context of the victim's browser session, potentially leading to session hijacking (CWE-79). The issue is resolved in version 3.7.0.

Affected products

  • LabRedesCefetRJ WeGIA < 3.7.0

Timeline

  • 2026-04-24: advisory: GitHub security advisory published by developer
  • 2026-05-11: disclosed: CVE published to NVD dataset
  • 2026-05-11: patched: Fix confirmed available in version 3.7.0

References

Related threats