5.4
CVE-2025-53541
- EPSS 0.21%
- Veröffentlicht 29.07.2025 19:27:38
- Zuletzt bearbeitet 05.08.2025 14:19:08
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Tuleap is vulnerable to XSS attacks when displaying the children of a parent artifact
Tuleap is an Open Source Suite created to facilitate management of software development and collaboration. In Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3, malicious users with some control over certain artifacts could insert malicious code when displaying the children of a parent artifact to force victims to execute the uncontrolled code. This is fixed in version Tuleap Community Edition prior to version 16.9.99.1751892857 and Tuleap Enterprise Edition prior to 16.8-5 and 16.9-3.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.106 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
|
| security-advisories@github.com | 5.4 | 2.3 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
https://github.com/Enalean/tuleap/security/advisories/GHSA-6r66-j76j-rwhw
https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=c1aec8247697d63dc4af791ecd6bd70d105ded08
https://tuleap.net/plugins/tracker/?aid=43693
http://github.com/Enalean/tuleap/commit/c1aec8247697d63dc4af791ecd6bd70d105ded08