GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 18.11, < 18.11.1
A vulnerability exists in GitLab CE/EE versions 18.11 prior to 18.11.1, where improper input validation in the Mermaid sandbox could have allowed an authenticated user to inject unauthorized content into another user's browser under certain conditions.
Exploitation of this vulnerability could lead to cross-user content injection, allowing an authenticated user to load unauthorized content into another user's browser.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.