CVE-2026-23731 Details
Description
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Options is missing andContent-Security-Policy with frame-ancestors directive is not configured. Because of this, an attacker can load any WeGIA page inside a malicious HTML document, overlay deceptive elements, hide real buttons, or force accidental interaction with sensitive workflows. This vulnerability is fixed in 3.6.2.
A clickjacking vulnerability has been identified in WeGIA, a web management application for charitable institutions, in versions prior to 3.6.2. The application lacks proper HTTP headers to protect against framing attacks, specifically missing the X-Frame-Options header and not configuring the Content-Security-Policy to restrict frame ancestors. This absence allows attackers to embed WeGIA pages within malicious HTML documents, overlay deceptive elements, conceal genuine buttons, or inadvertently trigger interactions with sensitive processes.
Users can update to WeGIA version 3.6.2 or later, where this vulnerability has been fixed. Instructions for downloading the latest version are available on the WeGIA GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/LabRedesCefetRJ/WeGIA/pull/1333 | [email protected] | Issue TrackingPatch |
| https://github.com/LabRedesCefetRJ/WeGIA/releases/tag/3.6.2 | [email protected] | Release Notes |
| https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-99qp-hjvh-c59q | [email protected] | ExploitMitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wegia wegia | < 3.6.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 30, 2026 | Initial Analysis | [email protected] |
| Jan 16, 2026 | New CVE Received | [email protected] |