CVE-2021-28378Cross-site Scripting in Gitea

Severity
5.4MEDIUMNVD
EPSS
12.9%
top 5.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 15
Latest updateAug 21

Description

Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

Affected Packages2 packages

NVDgitea/gitea1.13.01.13.4+1
Gocode.gitea.io/gitea< 1.13.4

Patches

🔴Vulnerability Details

3
OSV
Cross-site Scripting in Gitea in code.gitea.io/gitea2024-08-21
GHSA
Cross-site Scripting in Gitea2021-09-27
OSV
Cross-site Scripting in Gitea2021-09-27