MEDIUM
CVE-2019-15724
CVSS
6.1
Description
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
Summary dbcve.org
GitLab Community and Enterprise Edition versions 11.10 through 12.2.1 contain an HTML injection vulnerability in label descriptions. Attackers can inject arbitrary HTML into label description fields due to insufficient input sanitization, potentially enabling phishing attacks or defacement.
Mitigation
Upgrade to GitLab 12.2.2 or later which includes proper HTML sanitization for label description fields. If immediate upgrade is not possible, implement input validation to sanitize HTML tags in label descriptions.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
1.23%
Probability of exploitation in next 30 days
67.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.