MEDIUM

CVE-2021-22232

Gitlab GitLab 2021-07-06 CVSS v3.1
CVSS
5.4

Description

HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE

Summary dbcve.org

HTML injection vulnerability in GitLab Community Edition allowing attackers to inject malicious HTML/script content via the user profile 'full name' field. The injected content would be rendered in other users' browsers when viewing the attacker's profile, potentially leading to session hijacking or phishing attacks.

Mitigation

Upgrade GitLab CE to versions 13.11.6, 13.12.6, 14.0.2 or later. Implement input validation and output encoding on the full name field as a defense-in-depth measure.

Weakness (CWE)

CWE-74 Injection

EPSS Score

0.75%
Probability of exploitation in next 30 days
53.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE