CVE-2026-23728 Details
Description
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an Open Redirect vulnerability was identified in the /WeGIA/controle/control.php endpoint of the WeGIA application, specifically through the nextPage parameter when combined with metodo=listarTodos and nomeClasse=DestinoControle. The application fails to validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. This vulnerability is fixed in 3.6.2.
An open redirect vulnerability exists in the WeGIA application, specifically in the control.php endpoint prior to version 3.6.2. The issue arises through the nextPage parameter, when used with metodo=listarTodos and nomeClasse=DestinoControle. The application does not properly validate or restrict the nextPage parameter, allowing attackers to redirect users to arbitrary external websites. This vulnerability could be exploited for phishing attacks, credential theft, malware distribution, and social engineering, taking advantage of the trusted WeGIA domain.
Users are advised to update to WeGIA version 3.6.2, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LabRedesCefetRJ/WeGIA/pull/1333 | [email protected] | Issue TrackingPatch |
| https://github.com/LabRedesCefetRJ/WeGIA/releases/tag/3.6.2 | [email protected] | Release Notes |
| https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-jf25-p56f-wpgh | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wegia wegia | < 3.6.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | Initial Analysis | [email protected] |
| Jan 16, 2026 | New CVE Received | [email protected] |