HTML Injection Vulnerability in GitLab CE/EE Allows Email Address Field Manipulation

HTML Injection Vulnerability in GitLab CE/EE Allows Email Address Field Manipulation

CVE-2023-2200 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

An issue has been discovered in GitLab CE/EE affecting all versions starting from 7.14 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to inject HTML in an email address field.

Learn more about our Web Application Penetration Testing UK.