Stored Cross-Site Scripting (XSS) Vulnerability in Gogs Versions v0.6.5 - v0.12.10 Leading to Account Takeover

Stored Cross-Site Scripting (XSS) Vulnerability in Gogs Versions v0.6.5 - v0.12.10 Leading to Account Takeover

CVE-2022-32174 · CRITICAL Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

Learn more about our Web Application Penetration Testing UK.