Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:29715
HistoryMar 16, 2021 - 4:48 a.m.

Cross-site Scripting (XSS)

2021-03-1604:48:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11
cross-site scripting
vulnerability
javascript
browser
contextpopup.js
gitea

EPSS

0.001

Percentile

26.4%

github.com/go-gitea/gitea is vulnerable to cross-site scripting. An attacker is able to inject and execute arbitrary Javascript in the user’s browser via the issuePopup function in contextpopup.js in some situations.