VYPR
Medium severity6.1NVD Advisory· Published Jul 11, 2019· Updated Jun 17, 2026

CVE-2019-1010314

CVE-2019-1010314

Description

Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
code.gitea.io/giteaGo
>= 1.7.2, < 1.7.41.7.4

Affected products

4
  • Go Gitea/Giteav53 versions
    1.7.2, 1.7.3+ 2 more
    • (no CPE)range: 1.7.2, 1.7.3
    • cpe:2.3:a:gitea:gitea:1.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:gitea:gitea:1.7.3:*:*:*:*:*:*:*
  • ghsa-coords
    Range: >= 1.7.2, < 1.7.4

Patches

Vulnerability mechanics

References

8

News mentions

0

No linked articles in our index yet.