← Back

CVE-2025-30755

nvd nist
Published: Sep 19, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: secalert_us@oracle.com (Secondary)

Description

OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The application reflects unsanitized user input into the HTML output.

Affected (1)

Products: Oracle: Opengrok
1 product
Opengrok
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.14.1

Timeline

No history available yet.