MEDIUM

CVE-2022-1175

Gitlab GitLab 2022-04-04 CVSS v3.1
CVSS
6.1

Description

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

82%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE