CVE-2021-45329

MEDIUM6.1EPSS 0.34%

Cross-site Scripting in Gitea in github.com/go-gitea/gitea

Published: 2/10/2022Modified: 4/3/2025
Also known as:GHSA-r3gq-wxqf-q4ghBIT-gitea-2021-45329GO-2022-0314

Description

Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (6)