Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:35408
HistoryMay 06, 2022 - 8:40 a.m.

Cross-Site Scripting (XSS)

2022-05-0608:40:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.001 Low

EPSS

Percentile

24.1%

github.com/gogs/gogs is vulnerable to cross-site scripting. The vulnerability exists due to the lack of sanitization in the runWeb function of web.go, allowing an attacker to inject and execute malicious javascript.