PT-2023-19309 · Tuleap · Tuleap

Nicolas Terray

+1

·

Published

2023-04-20

·

Updated

2023-05-02

·

CVE-2023-23938

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap versions prior to 14.5.99.4
Description The issue is a cross-site scripting attack that can be injected in the name of a color of select box values of a tracker and then reflected in the tracker administration. Administrative privilege is required, but an attacker with tracker administration rights could use this to force a victim to execute uncontrolled code in the context of their browser.
Recommendations For versions prior to 14.5.99.4, upgrade to Tuleap Community Edition version 14.5.99.4 to address the issue. As a temporary workaround, consider restricting access to the tracker administration to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-23938
GHSA-MQJM-C6RM-9H87

Affected Products

Tuleap