WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web application prior to version 3.4.5. The control.php endpoint allows to specify an arbitrary URL via the `nextPage` parameter, leading to an uncontrolled redirection. Version 3.4.5 contains a fix for the issue.
References
Link | Resource |
---|---|
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5 | Exploit Vendor Advisory |
https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5 | Exploit Vendor Advisory |
Configurations
History
18 Jul 2025, 20:08
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* | |
First Time |
Wegia
Wegia wegia |
|
References | () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5 - Exploit, Vendor Advisory |
15 Jul 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-14 23:15
Updated : 2025-07-18 20:08
NVD link : CVE-2025-53821
Mitre link : CVE-2025-53821
CVE.ORG link : CVE-2025-53821
JSON object : View
Products Affected
wegia
- wegia
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')