CVE-2024-6886
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.
- Affected products
- Gitea
- Fix
- Available
- CVSS 4.0
- 10.0 CRITICAL
- EPSS
- 33.0% (98th percentile)
- Weakness
- CWE-79
- NVD status
- Deferred
- Published
- 2024-08-06
- Attack patterns
- CAPEC-592
- Entry point
- description request body
- Path
- /{username}/{repo_name}/settings
CVE-2024-6886 at NVD
3 known exploits for CVE-2024-6886
Proof-of-concept code and exploit modules indexed by Sploitus