Description


An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

Related CPE's


a

gitlab

gitlab

2

Weaknesses



CWE-79

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

8.7 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-07-28T13:15:07.600Z

3 years ago

Last modified

2024-11-21T05:41:48.930Z

1 year ago