Jenkins Gitlab Hook 1.4.2 and earlier does not escape project names in the build_now endpoint, resulting in a reflected cross-site scripting vulnerability.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view