Wegia · Wegia · CVE-2026-45025
**Name of the Vulnerable Software and Affected Versions**
WeGIA versions prior to 3.7.3
**Description**
A Stored Cross-Site Scripting (XSS) issue exists where an authenticated user can inject malicious JavaScript into the 'Etapas de um Processo' page via the endpoint 'html/atendido/etapa processo.php'. This script executes when users access the page, potentially leading to session hijacking and account takeover. Stored Cross-Site Scripting is a type of vulnerability where the malicious script is permanently stored on the target server.
**Recommendations**
Update to version 3.7.3.