MEDIUM

CVE-2019-12444

Gitlab GitLab 2020-03-10 CVSS v3.1
CVSS
6.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

Summary dbcve.org

A persistent cross-site scripting (XSS) vulnerability exists in GitLab Community and Enterprise Edition versions 8.9 through 11.11. The wiki pages feature lacks proper input validation, allowing attackers to inject malicious JavaScript code that persists and executes when other users view the compromised wiki content.

Mitigation

Upgrade GitLab to a version beyond 11.11 that includes the patched input validation for wiki pages, or apply the official security patch if available for the affected versions.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.69%
Probability of exploitation in next 30 days
51.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE