xsspresso
xsspresso
Tags/ CVE-2024-38472

CVE-2024-38472

1 writeup tagged with CVE-2024-38472

WebMediumLinux

HTB — Cat

Apache mod_rewrite CVE-2024-38472 XSS in redirect. Stored XSS steals admin cookie for Gitea access. SQLite injection and Gitea hook RCE for root.

#XSS#CVE-2024-38472#Gitea
Feb 1, 2025HackTheBox