WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=FuncionarioControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This issue is fixed in version 3.5.0.
CVSS
No CVSS.
References
Configurations
No configuration.
History
03 Oct 2025, 16:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-m64v-hm7q-33wr - |
02 Oct 2025, 21:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-10-02 21:16
Updated : 2025-10-03 16:16
NVD link : CVE-2025-61606
Mitre link : CVE-2025-61606
CVE.ORG link : CVE-2025-61606
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')