PT-2022-21137 · Gogs · Gogs

Published

2022-10-11

·

Updated

2025-05-16

·

CVE-2022-32174

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Gogs versions v0.6.5 through v0.12.10
Description The issue is related to Stored Cross-Site Scripting (XSS) that can lead to an account takeover.
Recommendations For versions v0.6.5 through v0.12.10, update to a version that is not affected by this issue to prevent account takeover due to Stored Cross-Site Scripting (XSS).

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-32174
GHSA-MCJJ-2FVQ-MC3R
GO-2022-1060

Affected Products

Gogs