Impact
A flaw in Gitea prior to version 1.25.5 permits an authenticated user to alter another user's primary email address, bypassing the expected restriction on account data changes. The weakness, identified as CWE‑639, can be leveraged to redirect notification traffic, impersonate a user, or facilitate further social‑engineering attacks. The primary impact is that an attacker who succeeds can take over the victim's account or at least hijack communications intended for that account.
Affected Systems
The Gitea open‑source Git server is affected. All releases before 1.25.5 are vulnerable, as no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 signals high severity while the EPSS score of less than 1 % indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated session and is executed through the normal web interface by using the email change function. Based on the description, the attack vector is inferred as an authenticated, internal user action that can modify another user's primary email address.
OpenCVE Enrichment