Record summary

CVE-2024-6886 has a selected CVSS score of 10.0 (critical); EIP currently links 1 Nuclei template.

Description

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 6, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List1.22.0affected

Default status: unaffected

CVE List1.22.0affected
GitHub AdvisoryBefore 1.22.1 · Fixed in 1.22.1affected

Nuclei templates

1
ProjectDiscoveryMEDIUMGitea 1.22.0 - Cross-Site ScriptingCVSS 6.7

Gitea 1.22.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to inject malicious scripts that get stored on the server and executed in the context of another user's session.

Impact

Authenticated attackers can inject malicious JavaScript into repository descriptions that executes in the context of other users' sessions when they view the repository.

Remediation

Update Gitea to version 1.22.1 or later to address the stored XSS vulnerability.

WeaknessesCWE-79
Authorssoonghee2
Template tagscvecve2024giteaxssauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
CPE: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

6