PT-2022-20500 · Tuleap · Tuleap
Nicolas Terray
+1
·
Published
2022-06-29
·
Updated
2022-07-15
·
CVE-2022-31063
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Tuleap versions prior to 13.9.99.111
Description
The issue arises from the improper escaping of a document's title in the search result of the MyDocmanSearch widget and in the administration page of locked documents. This could allow a malicious user, who has the capability to create a document, to force a victim to execute uncontrolled code.
Recommendations
For versions prior to 13.9.99.111, upgrade to a version that contains the fix for this issue.
At the moment, there is no information about other mitigation measures for this issue.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tuleap