MEDIUM

CVE-2022-1948

Gitlab GitLab 2022-07-28 CVSS v3.1
CVSS
5.4

Description

An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.

Summary dbcve.org

GitLab 15.0 before 15.0.1 fails to validate input in the quick actions feature related to contact details, allowing attackers to inject malicious HTML that executes as cross-site scripting (XSS) when other users view the contact information.

Mitigation

Upgrade GitLab to version 15.0.1 or later, which contains the fix for proper input validation in quick actions.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

1.02%
Probability of exploitation in next 30 days
62th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE