← back
CVE-2022-32174criticalCWE-79

Gogs - XSS

40Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 9epss 58%
exploitation probability
58%top 1% of all CVEs
observed exploitation
nono source reports it
In short

Gogs versions 0.6.5 to 0.12.10 allow attackers to inject malicious scripts that are permanently stored on the site. When other users view the affected page, the scripts execute in their browsers, potentially allowing attackers to steal their accounts.

Technical detail

Stored XSS vulnerability in Gogs allowing persistent injection of malicious JavaScript across multiple user sessions. The vulnerability enables account takeover by capturing session tokens or credentials when victims access contaminated content. Affects versions v0.6.5 through v0.12.10.

Summary generated and translated by AI from the official description.
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
gogs · gogs