CVE-2026-35475 MEDIUM

CVE-2026-35475: WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']

Vendor Labredescefetrj
Product WeGIA
Weakness CWE-601 · Open redirect
Published April 6, 2026
Last update April 7, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, the redirect parameter is taken directly from $_GET with no URL validation or whitelist check, then used verbatim in a header("Location: ...") call. This vulnerability is fixed in 3.6.9.

Key dates

02Disclosure timeline

April 6, 2026 CVE published
April 7, 2026 Record updated