Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.Referenceshttps://www.gitlab.com/2014/01/30/xss-vulnerability-in-gitlab/http://www.securityfocus.com/bid/64490http://www.exploit-db.com/exploits/30329https://exchange.xforce.ibmcloud.com/vulnerabilities/89932