Stored XSS in merge request pages
Link: https://hackerone.com/reports/409380
By: @8ayacDetails: Summary: I found a Stored XSS in merge request pages.
Description:
The exploit is via the parameter merge_request[source_branch] of the request to create a New Merge Request.
Steps To Reproduce:
- Sign ikn to GitLab.
- Click the "[+]" icon.
- Click "New Project".
- Fill out "Project name" form with "test-project".
- Check the radio button of "Public".
- Check the "Initialize repository with a README".
- Click "Create project" button.
- Go to "http(s)://{GitLab host}/{user id}/test-project/branches/new".
- Fill out each form as follows:
- Branch name: test-branch
- Create from: master
- Click "Create branch" button.
- Go to "http://{GitLab host}/{user id}/test-project/merge_requests".
- Click "Create merge request" button.
- Click "Submit merge request" button.
- Intercept the request.
- Change the
merge_request[source_branch]parameter's value to<img/src=x onerror=alert(1)> - Send the request.
Note: This behavior can be reproduced on all modern browsers.
Impact
The security impact is the same as any typical Stored XSS.
Thank you.
Merge Requests
Edited by Paul Slaughter
