← Back to browse · API

CVE-2024-1451

Severity
HIGH
CVSS
8.7
EPSS
0.51467
Risk score
52.81
CISA KEV
No
PoC
No
Published
2024-02-21
Modified
2026-05-23
First seen
2026-08-07
Aliases
EUVD-2024-17203, GHSA-XXCC-244V-RJ6X
Products
GitLab:GitLab 16.9.0 <16.9.1
Sources
euvd EUVD-2024-17203

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

References