Skip to main content

CVE-2025-6695: Wegia XSS Vulnerability in Categoria Module

CVE-2025-6695 is a cross-site scripting vulnerability in Wegia 3.4.0 affecting the Additional Categoria component. Attackers can exploit this flaw remotely to inject malicious scripts. This article covers technical details, impact analysis, and mitigation strategies.

Published:

CVE-2025-6695 Overview

CVE-2025-6695 is a stored cross-site scripting (XSS) vulnerability in LabRedesCefetRJ WeGIA version 3.4.0. The flaw resides in the /html/matPat/adicionar_categoria.php endpoint, specifically within the Additional Categoria component. Attackers can inject arbitrary script content through the Insira a nova categoria parameter. The issue is classified under CWE-79 and is exploitable remotely over the network with low privileges. A public proof-of-concept has been disclosed. The vendor was contacted before public disclosure but did not respond.

Critical Impact

Authenticated attackers can inject persistent JavaScript into the WeGIA application, enabling session theft, credential harvesting, or unauthorized actions performed in the context of victim users.

Affected Products

  • LabRedesCefetRJ WeGIA 3.4.0
  • Component: Additional Categoria (/html/matPat/adicionar_categoria.php)
  • Parameter: Insira a nova categoria

Discovery Timeline

  • 2025-06-26 - CVE-2025-6695 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-6695

Vulnerability Analysis

WeGIA is an open-source web manager for philanthropic institutions. The vulnerability affects the material and patrimony (matPat) module, where the application accepts user-supplied category names without proper output encoding or input sanitization. When the Insira a nova categoria field is submitted through adicionar_categoria.php, the payload is stored and later rendered in the browser as HTML.

Because the injected content executes in the context of the WeGIA application, attackers can run arbitrary JavaScript against any user who views the affected page. The exploit requires network access and low-privilege authentication, and it depends on user interaction to trigger execution.

Exploit Prediction Scoring System (EPSS) data indicates a low near-term probability of exploitation activity. A public proof-of-concept exists in the GitHub PoC Repository.

Root Cause

The root cause is missing input validation and output encoding on the category name parameter in adicionar_categoria.php. The application stores attacker-controlled input directly and reflects it into rendered HTML without contextual escaping, matching the pattern described by CWE-79: Improper Neutralization of Input During Web Page Generation.

Attack Vector

An authenticated attacker submits a crafted payload containing HTML or JavaScript to the Insira a nova categoria field. When another user loads the page containing the stored category, the browser parses and executes the injected script. This can lead to session cookie theft, forced navigation, unauthorized administrative actions, or defacement of the interface. See the VulDB entry #313961 for additional technical context.

Detection Methods for CVE-2025-6695

Indicators of Compromise

  • Unexpected <script>, <img onerror=>, or event-handler attributes stored in WeGIA category records
  • HTTP POST requests to /html/matPat/adicionar_categoria.php containing HTML tags or JavaScript event handlers in the category parameter
  • Outbound requests from user browsers to attacker-controlled domains after opening the category management pages
  • Anomalous session cookie access or exfiltration attempts originating from WeGIA users

Detection Strategies

  • Inspect the WeGIA database for stored category values containing HTML markup, script tags, or JavaScript URI schemes
  • Deploy web application firewall (WAF) rules that flag or block script tags and event handlers on POST parameters to adicionar_categoria.php
  • Review web server access logs for POST bodies containing encoded XSS payloads such as %3Cscript%3E or onerror=

Monitoring Recommendations

  • Enable request body logging on the WeGIA application server for matPat endpoints
  • Alert on Content Security Policy (CSP) violation reports referencing the WeGIA origin
  • Monitor authenticated user sessions for concurrent logins or geographically improbable access patterns following category submissions

How to Mitigate CVE-2025-6695

Immediate Actions Required

  • Restrict access to the WeGIA matPat module to trusted administrative users only
  • Audit existing category records and remove any entries containing HTML or script content
  • Place the WeGIA instance behind a WAF configured with XSS filtering rules until an upstream fix is available
  • Enforce a strict Content Security Policy that disables inline script execution

Patch Information

No vendor patch is referenced in the NVD entry at time of publication. The vendor did not respond to disclosure attempts. Track the VulDB advisory #313961 and the WeGIA project repository for future updates and apply fixes as soon as they are released.

Workarounds

  • Disable or remove the adicionar_categoria.php functionality if it is not required for operations
  • Apply server-side input validation to reject HTML metacharacters in category names via a reverse proxy or WAF rule
  • Configure HTTP response headers X-XSS-Protection, X-Content-Type-Options: nosniff, and a restrictive Content-Security-Policy to reduce exploitability
  • Set the HttpOnly and Secure flags on session cookies to limit script-based session theft
bash
# Example nginx configuration hardening for the WeGIA application
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'" always;
add_header X-Content-Type-Options "nosniff" always;
add_header X-Frame-Options "SAMEORIGIN" always;

# Block obvious XSS payloads targeting the vulnerable endpoint
location /html/matPat/adicionar_categoria.php {
    if ($request_method = POST) {
        if ($request_body ~* "(<script|onerror=|javascript:)") {
            return 403;
        }
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.