Skip to content

Reflected XSS in optimistic comment posting

Closely related to https://gitlab.com/gitlab-org/gitlab-ce/issues/36979

  1. Set your name to Appel<script>alert("XSS via name in profile")</script>
  2. Post a comment

xsspoc

Edited by Robert Speicher