Impact
A flaw in Gitea prior to version 1.25.5 permits an authenticated user to alter another user’s primary email address, bypassing the expected restriction on account data changes. The weakness, identified as CWE‑639, enables unauthorized modification of a user’s primary email, which could allow an attacker to assume control of the user’s account or redirect messages intended for that user. The primary impact is the risk of account takeover or ensuring communication is sent to a compromised address.
Affected Systems
The Gitea open‑source Git server is affected. All releases before 1.25.5 are vulnerable, as no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 signals high severity while the EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session and is executed through the normal web interface by using the email change function. Based on the description, the attack vector is inferred as an authenticated, internal user action that can modify another user’s primary email address.
OpenCVE Enrichment