CVE-2018-16050

MEDIUM

GitLab 11.1.x < 11.1.5 and 11.2.x < 11.2.2 - Stored Cross-Site Scripting in Merge Request Changes View

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

References (2)

Core 2
Core References
Exploit, Issue Tracking, Vendor Advisory x_refsource_confirm
https://gitlab.com/gitlab-org/gitlab-ce/issues/49085

Scores

CVSS v3 6.1
EPSS 0.0007
EPSS Percentile 21.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 10.7.0 - 10.7.7 (2 CPE variants)
Published Oct 03, 2018
Tracked Since Feb 18, 2026