Cross-site scripting in Gitea - CVE-2019-1010314
Published: July 11, 2019 / Updated: August 8, 2020
Gitea
The Gitea Authors
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.