Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/cc3305/cve-2023-2825
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubcc3305/cve-2023-2825

CVE-2023-2825

Exploit script for CVE-2023-2825, an unauthenticated directory traversal vulnerability in GitLab 16.0.0 allowing arbitrary file read on servers with public nested group projects.

View Repository
2 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2023-2825

(Unauthenticated) Directory traversal leads to file read.

Summary of the CVE

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

Affected Versions

  • Gitlab Gitlab 16.0.0 Community Edition
  • Gitlab Gitlab 16.0.0 Enterprise Edition

Anomalies

Unauthenticated if there already is a repo with nested groups, otherwise a account with permission to create groups is needed.

References

  • Github POC - OccamSec, May 25 2023
  • Gitlab Report - pwnie, May 20 2023
  • CVE-details - CVSS Score 10.0
Download Tool