VYPR
Critical severity9.3NVD Advisory· Published Mar 20, 2026· Updated Jun 17, 2026

CVE-2026-33135

CVE-2026-33135

Description

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which is directly echoed into the HTML response without any sanitization or encoding. The script /html/memorando/novo_memorandoo.php reads HTTP GET parameters to display dynamic success messages to the user. At approximately line 273, the code checks if $_GET['msg'] equals 'success'. If true, it directly concatenates $_GET['sccs'] into an HTML alert and outputs it to the browser. This issue has been fixed in version 3.6.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Wegia/Wegia2 versions
    cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*range: <3.6.7
    • (no CPE)range: <=3.6.6
  • LabRedesCefetRJ/Wegiallm-fuzzy2 versions
    <=3.6.6+ 1 more
    • (no CPE)range: <=3.6.6
    • (no CPE)range: < 3.6.7

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.