Impact
A remote attacker can exploit a flaw in the SimpleXMLElement usage within GitList 2.0.0, causing the application to crash or become unresponsive. The weakness in the XML parsing component can be triggered by a crafted XML payload, leading to the consumption of server resources and denying legitimate users access. This issue falls under the CWE-404 category of unhandled error conditions.
Affected Systems
The vulnerability affects the GitList software developed by klaussilveira. Versions up to 2.0.0 are impacted, while the 3.0.0-beta release provides the necessary fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. Although the EPSS score is not available, the vulnerability is confirmed as publicly exploitable and can be executed remotely. It is currently not listed in the CISA KEV catalog, but the availability of a public exploit and the remote nature of the attack suggest a non‑negligible risk of denial of service events.
OpenCVE Enrichment