MEDIUM
CVE-2022-1948
CVSS
5.4
Description
An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.
Summary dbcve.org
GitLab 15.0 before 15.0.1 fails to validate input in the quick actions feature related to contact details, allowing attackers to inject malicious HTML that executes as cross-site scripting (XSS) when other users view the contact information.
Mitigation
Upgrade GitLab to version 15.0.1 or later, which contains the fix for proper input validation in quick actions.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.02%
Probability of exploitation in next 30 days
62th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.