MEDIUM
CVE-2019-12444
CVSS
6.1
Description
An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.
Summary dbcve.org
A persistent cross-site scripting (XSS) vulnerability exists in GitLab Community and Enterprise Edition versions 8.9 through 11.11. The wiki pages feature lacks proper input validation, allowing attackers to inject malicious JavaScript code that persists and executes when other users view the compromised wiki content.
Mitigation
Upgrade GitLab to a version beyond 11.11 that includes the patched input validation for wiki pages, or apply the official security patch if available for the affected versions.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.