ronin-rb / community-pocs

A repository of PoCs for ronin-exploits
https://ronin-rb.dev
GNU General Public License v3.0
0 stars 2 forks source link

Add PoC exploit for CVE-2023-7028 #8

Open postmodern opened 4 months ago

postmodern commented 4 months ago

Add a PoC exploit for CVE-2023-7028, where a specially crafted HTTP request can cause GitLab to send password reset emails to an arbitrary email address to trigger a password reset and account hijack.

Reference PoCs

Vuln Apps

How to Submit a PoC

See the CONTRIBUTING file for instructions on how to submit a PoC exploit.