MEDIUM

CVE-2018-12605

Gitlab GitLab 2018-08-03 CVSS v3.0
CVSS
5.4

Description

An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.66%
Probability of exploitation in next 30 days
50th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE