CVE-2024-1451
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability in GitLab CE/EE versions 16.9 before 16.9.1 allows authenticated users to inject malicious JavaScript via crafted payloads in user profile fields. When other users view the compromised profile, the payload executes in their browsers, enabling session hijacking and arbitrary actions.
Mitigation
Upgrade to GitLab 16.9.1 or later to receive the patch. As an interim measure, restrict or sanitize user profile field inputs until the upgrade can be completed.