CVE-2023-7028

CRITICAL KEV NUCLEI LAB

GitLab Password Reset Account Takeover

Title source: metasploit

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

Exploits (19)

exploitdb WORKING POC
by 0xB455 · textremotejava
https://www.exploit-db.com/exploits/51889
nomisec WORKING POC 243 stars
by Vozec · remote
https://github.com/Vozec/CVE-2023-7028
nomisec WORKING POC 58 stars
by RandomRobbieBF · remote
https://github.com/RandomRobbieBF/CVE-2023-7028
nomisec WORKING POC 4 stars
by Esonhugh · remote
https://github.com/Esonhugh/gitlab_honeypot
nomisec WORKING POC 3 stars
by duy-31 · remote
https://github.com/duy-31/CVE-2023-7028
nomisec WORKING POC 2 stars
by sariamubeen · remote
https://github.com/sariamubeen/CVE-2023-7028
nomisec WORKING POC 2 stars
by thanhlam-attt · remote
https://github.com/thanhlam-attt/CVE-2023-7028
nomisec WORKING POC 1 stars
by szybnev · remote
https://github.com/szybnev/CVE-2023-7028
nomisec WORKING POC 1 stars
by gh-ost00 · remote
https://github.com/gh-ost00/CVE-2023-7028
nomisec WORKING POC 1 stars
by hackeremmen · remote
https://github.com/hackeremmen/gitlab-exploit
nomisec SUSPICIOUS 1 stars
by Trackflaw · poc
https://github.com/Trackflaw/CVE-2023-7028-Docker
nomisec WORKING POC
by KameliaZaman · remote
https://github.com/KameliaZaman/Exploiting-GitLab-CVE-2023-7028
nomisec WORKING POC
by Sornphut · remote
https://github.com/Sornphut/CVE-2023-7028-GitLab
nomisec WORKING POC
by yoryio · poc
https://github.com/yoryio/CVE-2023-7028
nomisec WORKING POC
by soltanali0 · remote
https://github.com/soltanali0/CVE-2023-7028
nomisec WORKING POC
by mochammadrafi · remote
https://github.com/mochammadrafi/CVE-2023-7028
nomisec WORKING POC
by Shimon03 · remote
https://github.com/Shimon03/CVE-2023-7028-Account-Take-Over-Gitlab
nomisec WORKING POC
by googlei1996 · remote
https://github.com/googlei1996/CVE-2023-7028
metasploit WORKING POC
by h00die, asterion04 · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/http/gitlab_password_reset_account_takeover.rb

Nuclei Templates (1)

GitLab - Account Takeover via Password Reset
HIGHVERIFIEDby DhiyaneshDk,rootxharsh,iamnooob,pdresearch
Shodan: title:"Gitlab" || cpe:"cpe:2.3:a:gitlab:gitlab" || http.title:"gitlab"
FOFA: title="gitlab"

Scores

CVSS v3 10.0
EPSS 0.9327
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull gitlab/gitlab-ce:16.1.4-ce.0
docker pull gitlab/gitlab-ce:16.1.5-ce.0
+15 more repos

Details

CISA KEV 2024-05-01
VulnCheck KEV 2024-05-01
InTheWild.io 2024-05-01
ENISA EUVD EUVD-2023-59219
CWE
CWE-640
Status published
Products (1)
gitlab/gitlab 16.1.0 - 16.1.6 (2 CPE variants)
Published Jan 12, 2024
KEV Added May 01, 2024
Tracked Since Feb 18, 2026