Reflected Cross-Site Scripting Vulnerability in OpenGrok by Oracle
CVE-2025-21572
6.1MEDIUM
Summary
OpenGrok version 1.13.25 contains a reflected Cross-Site Scripting flaw occurring on the history view page due to inadequate management of path segments. This vulnerability allows attackers to inject malicious scripts through unsanitized user input, which is then reflected in the HTML output. This opens the door for potential exploitation, compromising user data and security.
Affected Version(s)
OpenGrok 1.13.25
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved