4.3
CVSSv2

CVE-2014-8683

Published: 21/11/2014 Updated: 09/10/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.8 allows remote malicious users to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.

Vulnerable Product Search on Vulmon Subscribe to Product

gogits gogs 0.3.1-9

gogits gogs 0.4.1

gogits gogs 0.4.2

gogits gogs 0.5.0

gogits gogs 0.5.2

gogits gogs

Exploits

Gogs markdown renderer suffers from a cross site scripting vulnerability Versions 031-9-g49dc57e are affected ...