CVE-2025-53821

WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirect vulnerability exists in the web application prior to version 3.4.5. The control.php endpoint allows to specify an arbitrary URL via the `nextPage` parameter, leading to an uncontrolled redirection. Version 3.4.5 contains a fix for the issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

History

18 Jul 2025, 20:08

Type Values Removed Values Added
CPE cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*
First Time Wegia
Wegia wegia
References () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5 - () https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-f5c2-jmm6-v2c5 - Exploit, Vendor Advisory

15 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-14 23:15

Updated : 2025-07-18 20:08


NVD link : CVE-2025-53821

Mitre link : CVE-2025-53821

CVE.ORG link : CVE-2025-53821


JSON object : View

Products Affected

wegia

  • wegia
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')