
🚨 Entity: CVE-2026-42872 in WeGIA <3.7.0. Reflected XSS via id_proceso parameter in lista_arquivos_etapa.php. Session hijacking, credential theft surface exposed. Upgrade to 3.7.0. https://0x2ed3bb60.xyz/threat/1890395c0d7ecfdf
Post summary
CVE-2026-42872 is a reflected XSS flaw in WeGIA <3.7.0 that can enable session hijacking and credential theft; upgrading to version 3.7.0 fixes the issue.
