High severity8.7NVD Advisory· Published Jul 28, 2022· Updated Jun 17, 2026
CVE-2022-1948
CVE-2022-1948
Description
An issue has been discovered in GitLab affecting all versions starting from 15.0 before 15.0.1. Missing validation of input used in quick actions allowed an attacker to exploit XSS by injecting HTML in contact details.
Affected products
5cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:15.0.0:*:*:*:enterprise:*:*:*
- (no CPE)range: <15.0.1
- (no CPE)range: >=15.0.0, <15.0.1
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1948.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/security/gitlab/-/issues/673nvdPermissions Required
- hackerone.com/reports/1578400nvdPermissions Required
News mentions
0No linked articles in our index yet.