MEDIUM
CVE-2020-13283
CVSS
5.4
Description
For GitLab before 13.0.12, 13.1.6, 13.2.3 a cross-site scripting vulnerability exists in the issues list via milestone title.
Summary dbcve.org
A stored cross-site scripting (XSS) vulnerability in GitLab allows authenticated users to inject malicious JavaScript code through milestone titles. When other users view the issues list, the injected payload executes in their browsers, potentially allowing session hijacking or data theft.
Mitigation
Upgrade GitLab to version 13.0.12, 13.1.6, 13.2.3 or later to patch the vulnerability. Until upgraded, restrict milestone creation permissions and warn users not to click on suspicious milestone links.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.85%
Probability of exploitation in next 30 days
56.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.