CVE-2024-1451

HIGH8.7EPSS 29.1%

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

發布日:2024/3/6修改日:2025/5/20

描述

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH8.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

參考連結(3)