MEDIUM
CVE-2019-19311
CVSS
5.4
Description
GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.
Summary dbcve.org
GitLab EE versions 8.14 through 12.5, 12.4.3, and 12.3.6 contain a stored Cross-Site Scripting (XSS) vulnerability in group and profile fields. User-supplied input in these fields is not properly sanitized or encoded when rendered, allowing malicious scripts to execute in the browsers of other users viewing these fields.
Mitigation
Upgrade to a patched GitLab version. As an interim control, implement proper output encoding and input validation on group and profile field rendering, or restrict field input through a WAF with XSS rules.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.73%
Probability of exploitation in next 30 days
52.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.