PT-2023-22815 · Unknown · Tuleap Open Alm

Tgerbet

+1

·

Published

2023-05-04

·

Updated

2023-05-10

·

CVE-2023-30619

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Tuleap Open ALM versions prior to 14.7.99.143
Description The title of an artifact is not properly escaped in the tooltip, allowing a malicious user with the capability to create an artifact or edit a field title to force a victim to execute uncontrolled code. A malicious user could exploit this issue by creating or editing an artifact with a specially crafted title.
Recommendations For versions prior to 14.7.99.143, update to version 14.7.99.143 or later to resolve the issue. As a temporary workaround, consider restricting the ability to create or edit artifacts and field titles to trusted users until the update is applied.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-30619
GHSA-7FM3-CR3G-5922

Affected Products

Tuleap Open Alm