Gogs
cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*
- <= 0.14.0+dev
A stored cross-site scripting vulnerability has been identified in Gogs, an open-source self-hosted Git service, in application versions through 0.14.0+dev. This vulnerability allows for the execution of client-side JavaScript. The issue arises from the use of an outdated component, pdfjs-1.4.20, located in public/plugins/.
Exploitation of this vulnerability allows for stored cross-site scripting, where uploaded JavaScript is executed in the context of the user.
To reproduce this vulnerability, upload a PDF file containing JavaScript into a repository. Then, click on the uploaded file to preview it. The JavaScript will execute in the user's browser.
Users can upgrade to Gogs version 0.13.3, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.