MEDIUM
CVE-2022-1175
CVSS
6.1
Description
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
82%
Probability of exploitation in next 30 days
99.6th percentile
References
http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html
Third Party Advisory, VDB Entry
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/issues/353370
Broken Link
https://hackerone.com/reports/1481207
Permissions Required, Third Party Advisory
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.