Record summary

CVE-2022-1175 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List>=14.4, <14.7.7affected
>=14.8, <14.8.5affected
>=14.9, <14.9.2affected

Proofs of concept

2

Catalogued exploits

ExploitDBGitLab 14.9 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby GreenwolfNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubGreenwolf/CVE-2022-1175Repository PoCby GreenwolfStars: 1Not analyzed1 file

1.2 KiB

GitHub

PoC details

References

5