MEDIUM
CVE-2021-22232
CVSS
5.4
Description
HTML injection was possible via the full name field before versions 13.11.6, 13.12.6, and 14.0.2 in GitLab CE
Summary dbcve.org
HTML injection vulnerability in GitLab Community Edition allowing attackers to inject malicious HTML/script content via the user profile 'full name' field. The injected content would be rendered in other users' browsers when viewing the attacker's profile, potentially leading to session hijacking or phishing attacks.
Mitigation
Upgrade GitLab CE to versions 13.11.6, 13.12.6, 14.0.2 or later. Implement input validation and output encoding on the full name field as a defense-in-depth measure.
Weakness (CWE)
CWE-74
Injection
EPSS Score
0.75%
Probability of exploitation in next 30 days
53.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.