packetstormsecurity.com
http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html CVE-2022-1175
HIGH
GitLab 14.9 - Stored Cross-Site Scripting (XSS)
Record summary
CVE-2022-1175 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GitLabBrowse GitLab / GitLab | CVE List | >=14.4, <14.7.7 | affected |
| >=14.8, <14.8.5 | affected | ||
| >=14.9, <14.9.2 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBGitLab 14.9 - Stored Cross-Site Scripting (XSS)ExploitDB exploitby GreenwolfNot analyzed1 file
Repository PoCs
GitHubGreenwolf/CVE-2022-1175Repository PoCby GreenwolfStars: 1Not analyzed1 file
References
5gitlab.comConfirmation
https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json gitlab.com
https://gitlab.com/gitlab-org/gitlab/-/issues/353370 hackerone.com
https://hackerone.com/reports/1481207 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1175