PT-2023-19309 · Tuleap · Tuleap

·

CVE-2023-23938

·

Published

2023-04-20

·

Updated

2023-05-02

CVSS v3.1

5.9

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Tuleap versions prior to 14.5.99.4
Description The issue is a cross-site scripting attack that can be injected in the name of a color of select box values of a tracker and then reflected in the tracker administration. Administrative privilege is required, but an attacker with tracker administration rights could use this to force a victim to execute uncontrolled code in the context of their browser.
Recommendations For versions prior to 14.5.99.4, upgrade to Tuleap Community Edition version 14.5.99.4 to address the issue. As a temporary workaround, consider restricting access to the tracker administration to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-23938
GHSA-MQJM-C6RM-9H87

Affected Products

Tuleap