ZeroHour

CVE-2021-45326

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
Description

Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.

Vendors
gitea
Products
gitea
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.