xsspresso
xsspresso
Tags/ Gitea

Gitea

2 writeups tagged with Gitea

WebMediumLinux

HTB — Cat

Apache mod_rewrite CVE-2024-38472 XSS in redirect. Stored XSS steals admin cookie for Gitea access. SQLite injection and Gitea hook RCE for root.

#XSS#CVE-2024-38472#Gitea
Feb 1, 2025HackTheBox
WebEasyLinux

HTB — Busqueda

Searchor 2.4.0 CLI eval() injection for code execution. Gitea instance found via Docker-compose, admin token for privileged script execution.

#Code Injection#eval()#Gitea
Nov 19, 2024HackTheBox