6.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Description
OpenGrok 1.14.1 has a reflected Cross-Site Scripting (XSS) issue when producing the cross reference page. This happens through improper handling of the revision parameter. The application reflects unsanitized user input into the HTML output.
Basic Information
ID
CVE-2025-30755
Source
oracle
Published
Sep 18, 2025 at 23:32
Affected Product
Vendor
Oracle Corporation
Product
OpenGrok
Version
1.14.1
Affected Versions
Oracle Corporation OpenGrok 1.14.1