MEDIUM🇵🇱 Wersja polska

CVE-2025-30203

CVSS 4.8v3.1pub. 2025-03-31upd. 2025-08-21

Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap allows cross-site scripting (XSS) via the content of RSS feeds in the RSS widgets. A project administrator or someone with control over an used RSS feed could use this vulnerability to force victims to execute uncontrolled code. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742562878 and Tuleap Enterprise Edition 16.5-5 and 16.4-8.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:N/I:L/A:L
  • Enalean Tuleap

    APP
    Enalean
    < 16.4-8< 16.5.99.174256287816.5 – 16.5-5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2018-17298CRITICAL9.8PL ✓same product

Enalean Tuleap: linki reset hasła nie są unieważniane po zmianie hasła

CVE-2018-7538CRITICAL9.8PL ✓same product

SQL Injection w module tracker platformy Enalean Tuleap

CVE-2024-30246HIGH7.6same product

Tuleap is an Open Source Suite to improve management of software developments and collaboration. A malicious u...

CVE-2022-31058HIGH7.2same product

Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration. In vers...

CVE-2021-43806HIGH8.8same product

Tuleap is a Libre and Open Source tool for end to end traceability of application and system developments. In ...