Description


A vulnerability classified as problematic has been found in LabRedesCefetRJ WeGIA 3.4.0. This affects an unknown part of the file /html/funcionario/cadastro_funcionario.php of the component Cadastro de Funcionário. The manipulation of the argument Nome/Sobrenome leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This is a different issue than CVE-2025-23030. The vendor was contacted early about this disclosure but did not respond in any way.

Related CPE's


References



https://vuldb.com/?ctiid.313965

Permissions RequiredVDB Entry

https://vuldb.com/?id.313965

Third Party AdvisoryVDB Entry

https://vuldb.com/?submit.597401

ExploitThird Party AdvisoryVDB Entry

Weaknesses



CWE-79CWE-94


CWE-79

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

3.5 · Low

  • CVSS V3.1

  • CVSS V3.0

  • CVSS V2.0

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2025-06-26T16:15:34.590

5 months ago

Last modified

2025-07-01T15:42:08.920

5 months ago