An issue has been discovered in GitLab affecting versions from 12.10 to 12.10.12 that allowed for a stored XSS payload to be added as a group name.
2020-10-02T20:15:12.393
2024-11-21T05:01:03.853
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 12.10.12 | Yes |
Application | gitlab | gitlab | < 12.10.12 | Yes |