Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2023-7028 — Exploit para CVE-2023-7028 - GitLab CE/EE | Kitploit
Herramientas/GitHubGitHub/yoryio/cve-2023-7028
Análisis de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebPruebas de PenetraciónAutenticaciónLabs y Práctica
GitHubyoryio/cve-2023-7028

CVE-2023-7028

Exploit para CVE-2023-7028 - GitLab CE/EE

Ver Repositorio
1hace 1 añoAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

CVE-2023-7028

⚠️ Este exploit es para fines defensivos y debe ser utilizado por profesionales de ciberseguridad para identificar posibles servidores GitLab vulnerables.

Descripción

CVE-2023-7028 - Toma de control de cuenta mediante restablecimiento de contraseña sin interacción del usuario en GitLab Community Edition y Enterprise Edition

gitlablogo

Productos y versiones afectados:

ProductoVersiones afectadas
GitLab Community Edition y Enterprise Edition< 16.1.6
< 16.2.9
< 16.3.7
< 16.4.5
< 16.5.6
< 16.6.4
< 16.7.2
  • CVSS: 10.0
  • Explotado activamente: SÍ
  • Parche: SÍ
  • Mitigación: NO

Ayuda

root@kitploit:~
usage: CVE-2023-7028.py [-h] -u URL -t TARGET -a ATTACKER

options:
  -h, --help            show this help message and exit
  -u URL, --url URL     GitLab URL (HTTP or HTTPS)
  -t TARGET, --target TARGET
                        Target email address
  -a ATTACKER, --attacker ATTACKER
                        Attacker email address

Ejemplo: python CVE-2023-7028.py -u https://gitlab.example.com -t [email protected] -a [email protected]

Laboratorio

Puedes usar la sala de Try Hack Me GitLab CVE-2023-7028 para probar el exploit, ya que ejecuta una versión vulnerable afectada por CVE-2023-7028.

Visión de los servidores GitLab según SHADOWSERVER:

map2

Referencias

  • GitLab Critical Security Release: 16.7.2, 16.6.4, 16.5.6
  • Over 5,300 GitLab servers exposed to zero-click account takeover attacks
  • Shadowserver GitLab Statistics
  • CVE-2023-7028 - AttackerKB
Descargar herramienta