Reflected Cross-Site Scripting Vulnerability in OpenGrok by Oracle
CVE-2025-21572

6.1MEDIUM

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
2 May 2025

Summary

OpenGrok version 1.13.25 contains a reflected Cross-Site Scripting flaw occurring on the history view page due to inadequate management of path segments. This vulnerability allows attackers to inject malicious scripts through unsanitized user input, which is then reflected in the HTML output. This opens the door for potential exploitation, compromising user data and security.

Affected Version(s)

OpenGrok 1.13.25

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.