PoC Index

CVE-2023-7028

KEVCRITICAL 10.0EPSS 94.6%

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which user account password reset emails could be delivered to an unverified email address.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS
94.65% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2024-05-01
Nuclei
high
Published
2024-01-12
Updated
2026-08-15

Proof-of-concept exploits (21)

Nuclei templates (1)

Metasploit modules (1)

ExploitDB entries (1)

References

Related