Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altering POST requests.
{
"cwe_ids": [
"CWE-352"
],
"github_reviewed": true,
"github_reviewed_at": "2022-02-14T23:01:01Z",
"severity": "HIGH",
"nvd_published_at": "2022-02-08T15:15:00Z"
}