MEDIUM
CVE-2020-10078
CVSS
6.1
Description
GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability exists in the merge request submission form of GitLab versions 12.1 through 12.8.1. Attackers can inject malicious JavaScript payloads into merge request fields that persist on the page, executing in the browsers of users who view the affected merge requests.
Mitigation
Upgrade GitLab to version 12.8.2 or later. Alternatively, apply any available security patches from GitLab. Review merge request inputs for existing malicious content.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.69%
Probability of exploitation in next 30 days
51.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.