← Back

CVE-2025-21572

nvd nist
Published: May 2, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: secalert_us@oracle.com (Secondary)

Description

OpenGrok 1.13.25 has a reflected Cross-Site Scripting (XSS) issue when producing the history view page. This happens through improper handling of path segments. The application reflects unsanitized user input into the HTML output.

Affected (1)

Products: Oracle: Opengrok
1 product
Opengrok
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.13.25

Timeline

No history available yet.