3.5
CVSSv2

CVE-2020-26407

Published: 10/12/2020 Updated: 11/12/2020
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

A XSS vulnerability exists in Gitlab CE/EE from 12.4 prior to 13.4.7, 13.5 prior to 13.5.5, and 13.6 prior to 13.6.2 that allows an malicious user to perform cross-site scripting to other users via importing a malicious project

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gitlab gitlab

Vendor Advisories

A cross-site scripting vulnerability exists in Gitlab CE/EE starting with 124 that allows an attacker to perform cross-site scripting to other users via importing a malicious project It is fixed in Gitlab versions 1362, 1355 and 1347 ...