WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=FuncionarioControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This issue is fixed in version 3.5.0.
Metrics
Affected Vendors & Products
References
History
Fri, 03 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 03 Oct 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Wegia
Wegia wegia |
|
Vendors & Products |
Wegia
Wegia wegia |
Thu, 02 Oct 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open Redirect vulnerability, identified in the control.php endpoint, specifically in the nextPage parameter (metodo=listarUmnomeClasse=FuncionarioControle). This vulnerability allows attackers to redirect users to arbitrary external domains, enabling phishing campaigns, malicious payload distribution, or user credential theft. This issue is fixed in version 3.5.0. | |
Title | WeGIA: Open Redirect Vulnerability in `control.php` endpoint | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-10-02T20:25:58.422Z
Updated: 2025-10-03T14:58:54.113Z
Reserved: 2025-09-26T16:25:25.151Z
Link: CVE-2025-61606

Updated: 2025-10-03T14:58:43.400Z

Status : Received
Published: 2025-10-02T21:16:01.490
Modified: 2025-10-03T16:16:20.680
Link: CVE-2025-61606

No data.