Writeup Exploits

68,122 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-19570 WRITEUP MEDIUM
GitLab 11.3-11.3.10, 11.4-11.4.7, 11.5 - Cross-Site Scripting via Unrecognized HTML Tags in Markdown Fields
GitLab CE/EE, versions 11.3 before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an XSS vulnerability in Markdown fields via unrecognized HTML tags.
CVSS 5.4
CVE-2018-19569 WRITEUP HIGH
GitLab CE/EE <11.3.11, <11.4.8, <11.5.1 - Auth Bypass
GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.
CVSS 8.8
CVE-2018-19496 WRITEUP MEDIUM
GitLab <11.3.11-11.5.1 - Privilege Escalation
An issue was discovered in GitLab Community and Enterprise Edition 10.x and 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access control vulnerability that permits a user with insufficient privileges to promote a project milestone to a group milestone.
CVSS 6.5
CVE-2018-19495 WRITEUP MEDIUM
GitLab < 11.3.11, 11.4.x < 11.4.8, 11.5.x < 11.5.1 - Server-Side Request Forgery via Prometheus Integration
An issue was discovered in GitLab Community and Enterprise Edition before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an SSRF vulnerability in the Prometheus integration.
CVSS 6.5
CVE-2018-19494 WRITEUP MEDIUM
GitLab <11.3.11-11.5.1 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is an incorrect access vulnerability that allows an unauthorized user to view private group names.
CVSS 4.3
CVE-2018-19493 WRITEUP MEDIUM
GitLab 11.x < 11.3.11, 11.4.x < 11.4.8, 11.5.x < 11.5.1 - Stored Cross-Site Scripting in Environment Pages
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.
CVSS 6.1
CVE-2018-19359 WRITEUP HIGH
GitLab <11.5.0-rc12, 11.4.6, 11.3.10 - Info Disclosure
GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.
CVSS 8.8
CVE-2018-18843 WRITEUP CRITICAL
GitLab 11.0.0-11.2.8 - Server-Side Request Forgery via Kubernetes Integration
The Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.
CVSS 10.0
CVE-2018-18643 WRITEUP MEDIUM
GitLab 11.2-11.4.6 - Stored Cross-Site Scripting
GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.
CVSS 6.1
CVE-2018-20012 WRITEUP MEDIUM
PHPCMF 4.1.3 - Cross-Site Scripting via Registration Page Input Field
PHPCMF 4.1.3 has XSS via the first input field to the index.php?s=member&c=register&m=index URI.
CVSS 4.8
CVE-2018-20752 WRITEUP CRITICAL
recon-ng < 4.9.5 - CSV Injection via Twitter Username Export
An issue was discovered in Recon-ng before 4.9.5. Lack of validation in the modules/reporting/csv.py file allows CSV injection. More specifically, when a Twitter user possesses an Excel macro for a username, it will not be properly sanitized when exported to a CSV file. This can result in remote code execution for the attacker.
CVSS 9.8
CVE-2018-5360 WRITEUP HIGH
libtiff < 4.0.6 - Out-of-bounds Read in ReadTIFFImage
LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.
CVSS 8.8
CVE-2018-5687 WRITEUP MEDIUM
NewsBee - Stored Cross-Site Scripting via Company Name Field
NewsBee allows XSS via the Company Name field in the Settings under admin/admin.php.
CVSS 4.8
CVE-2018-5784 WRITEUP MEDIUM
libtiff - Denial of Service via Crafted TIFF File
In LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted tif file. This occurs because the declared number of directory entries is not validated against the actual number of directory entries.
CVSS 6.5
CVE-2018-6003 WRITEUP HIGH
GNU Libtasn1 < 4.13 - Denial of Service via Unlimited Recursion in BER Decoder
An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS.
CVSS 7.5
CVE-2018-7476 WRITEUP MEDIUM
FineCMS 5.3.0 - Cross-Site Scripting via Linkage Import ID or LID Parameter
controllers/admin/Linkage.php in dayrui FineCms 5.3.0 has Cross Site Scripting (XSS) via the id or lid parameter in a c=linkage,m=import request to admin.php, because the xss_clean protection mechanism is defeated by crafted input that lacks a '<' or '>' character.
CVSS 6.1
CVE-2019-11605 WRITEUP HIGH
GitLab <11.8.10-11.10.3 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition 11.8.x before 11.8.10, 11.9.x before 11.9.11, and 11.10.x before 11.10.3. It allows Information Disclosure. A small number of GitLab API endpoints would disclose project information when using a read_user scoped token.
CVSS 7.5
CVE-2019-11549 WRITEUP MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. Gitaly has allows an information disclosure issue where HTTP/GIT credentials are included in logs on connection errors.
CVSS 6.5
CVE-2019-11548 WRITEUP MEDIUM
GitLab 5.4.0-11.8.9 - Unauthenticated Incorrect Access Control in Note Endpoint
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9. It has Incorrect Access Control. Unprivileged members of a project are able to post comments on confidential issues through an authorization issue in the note endpoint.
CVSS 5.4
CVE-2019-11547 WRITEUP MEDIUM
GitLab < 11.8.9, 11.9.x < 11.9.10, 11.10.x < 11.10.2 - Cross-Site Scripting via Merge Request Notification Email
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially lead to XSS issues.
CVSS 6.1
CVE-2019-11546 WRITEUP MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has a Race Condition which could allow users to approve a merge request multiple times and potentially reach the approval count required to merge.
CVSS 5.3
CVE-2019-11545 WRITEUP MEDIUM
GitLab CE <11.9.10, <11.10.2 - Info Disclosure
An issue was discovered in GitLab Community Edition 11.9.x before 11.9.10 and 11.10.x before 11.10.2. It allows Information Disclosure. When an issue is moved to a private project, the private project namespace is leaked to unauthorized users with access to the original issue.
CVSS 4.3
CVE-2019-11544 WRITEUP MEDIUM
GitLab <11.8.9-11.10.2 - Info Disclosure
An issue was discovered in GitLab Community and Enterprise Edition 8.x, 9.x, 10.x, and 11.x before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It allows Information Disclosure. Non-member users who subscribe to notifications of an internal project with issue and repository restrictions will receive emails about restricted events.
CVSS 4.3
CVE-2019-11000 WRITEUP MEDIUM
GitLab < 11.7.11, 11.8.x < 11.8.7, 11.9.x < 11.9.7 - Information Disclosure
An issue was discovered in GitLab Enterprise Edition before 11.7.11, 11.8.x before 11.8.7, and 11.9.x before 11.9.7. It allows Information Disclosure.
CVSS 6.5
CVE-2019-10640 WRITEUP HIGH
GitLab < 11.7.10, 11.8.x < 11.8.6, 11.9.x < 11.9.4 - Resource Consumption via .gitlab-ci.yml
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.
CVSS 7.5