Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxxw-9mfc-32jr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

EPSS

Процентиль: 27%
0.00092
Низкий

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
nvd
больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 through 11.11. A malicious user could execute JavaScript code on notes by importing a specially crafted project file. It allows XSS.

CVSS3: 5.4
debian
больше 5 лет назад

An issue was discovered in GitLab Community and Enterprise Edition 8.4 ...

EPSS

Процентиль: 27%
0.00092
Низкий