CVE-2019-15739

MEDIUM

GitLab 8.1-12.2.1 - Stored Cross-Site Scripting in Markdown Renderer

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

References (2)

Core 2
Core References

Scores

CVSS v3 6.1
EPSS 0.0016
EPSS Percentile 36.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 8.1.0 - 12.0.8 (2 CPE variants)
Published Sep 16, 2019
Tracked Since Feb 18, 2026