MEDIUM
CVE-2017-0924
CVSS
6.1
Description
Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.
Summary dbcve.org
GitLab Community Edition 10.2.4 lacks input validation in the labels component, allowing attackers to inject malicious scripts that gets stored and executed when other users view the labels - a persistent XSS vulnerability.
Mitigation
Implement proper input validation and output encoding on the labels component to sanitize user-supplied content before storage and before rendering.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.76%
Probability of exploitation in next 30 days
53.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.