peter bassill · operator
$ cve CVE-2022-1175 JSON

CVE-2022-1175 EXPLOIT

8.7
HIGH · CVSS 3.1 · EPSS 82% (pctl 100)

Patch early

A public exploit exists.

Description

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

Scoring

CVSS8.7 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
EPSS82% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-79
On CISA KEVno
Public exploityes
Published2022-04-04
Last modified2026-06-17

Affected (1)

VendorProduct
gitlabgitlab

Public exploits

SourceTitleDate
exploit-dbGitLab 14.9 - Stored Cross-Site Scripting (XSS)2022-04-26

References

→ the Explorer  ·  watch your stack  ·  NVD