PT-2022-20500 · Tuleap · Tuleap

Nicolas Terray

+1

·

Published

2022-06-29

·

Updated

2022-07-15

·

CVE-2022-31063

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap versions prior to 13.9.99.111
Description The issue arises from the improper escaping of a document's title in the search result of the MyDocmanSearch widget and in the administration page of locked documents. This could allow a malicious user, who has the capability to create a document, to force a victim to execute uncontrolled code.
Recommendations For versions prior to 13.9.99.111, upgrade to a version that contains the fix for this issue. At the moment, there is no information about other mitigation measures for this issue.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-31063
GHSA-4FX8-4FF3-96JF

Affected Products

Tuleap