NA

CVE-2024-1451

Published: 22/02/2024 Updated: 04/03/2024
CVSS v3 Base Score: 8.7 | Impact Score: 5.8 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 prior to 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing malicious users to perform arbitrary actions on behalf of victims."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab 16.9.0